Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard
A global organization is implementing a cloud security strategy that prioritizes the ability to automatically enforce security policies and respond to threats across its multi-cloud environment without human intervention. This includes automated patching, configuration drift detection, and incident response workflows. Which security automation and orchestration concept is being applied here?
- ACloud Security Posture Management (CSPM)
- BSecurity Information and Event Management (SIEM)
- CSecurity Orchestration, Automation, and Response (SOAR)
- DCloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: C. Security Orchestration, Automation, and Response (SOAR)
SOAR platforms integrate security tools and automate repetitive security tasks, orchestrating complex workflows for incident response, threat hunting, and security operations, directly aligning with the need for automated policy enforcement and threat response across a multi-cloud environment.
Why the other options are wrong
- A. CSPM focuses on identifying and remediating misconfigurations, which is a component, but not the overarching orchestration of automated response.
- B. SIEM collects and analyzes logs for detection, but doesn't inherently automate response or orchestration.
- D. CASB focuses on cloud service usage, DLP, and shadow IT, not the broad automation and orchestration of security operations.
Security Orchestration, Automation, and Response (SOAR)
A category of security software that enables organizations to collect security alerts, standardize incident response, and automate various security tasks and workflows.
- Integrates disparate security tools.
- Automates repetitive tasks, reducing manual effort.
- Orchestrates complex incident response playbooks.
Memory trick: SOAR makes cloud security fly on autopilot, responding to threats fast.