CompTIA Security+ (SY0-701)Security OperationsMedium

A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains. The device needs to automatically update its block list with new threat intelligence feeds. Which security tool would BEST facilitate this capability?

  1. ASecurity Orchestration, Automation, and Response (SOAR)
  2. BIntrusion Prevention System (IPS)
  3. CFirewall
  4. DWeb Application Firewall (WAF)
Show answer & explanation

Correct answer: A. Security Orchestration, Automation, and Response (SOAR)

A SOAR platform is designed to orchestrate and automate security operations. It can ingest threat intelligence feeds, parse them for IOCs, and then automatically push updates to various security tools, such as firewalls or IPS, to block malicious traffic.

Why the other options are wrong

  • B. An IPS can block traffic based on signatures and behavioral analysis, but like a firewall, it often needs a SOAR or similar platform to automatically consume and apply new threat intelligence feeds.
  • C. A firewall can block traffic based on IP/domain, but it typically requires manual configuration or integration with other tools for automatic threat intelligence updates.
  • D. A WAF protects web applications from specific web-based attacks; while it can block, it's not the primary tool for orchestrating broad threat intelligence updates to network devices.

Security Orchestration, Automation, and Response (SOAR)

A platform that combines orchestration, automation, and incident response capabilities to streamline security operations by integrating disparate security tools and automating repetitive tasks.

  • Automates incident response workflows
  • Integrates with diverse security tools
  • Ingests and acts on threat intelligence

Memory trick: SOAR is the brain connecting and automating security actions.

More Security Operations questions