Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium

A security operations center (SOC) team is struggling to keep up with the volume of security alerts generated by their cloud environment. They need a solution that can automatically collect security data from various cloud services, correlate events, and execute predefined incident response playbooks without human intervention for common, low-risk incidents. Which cloud security technology would best integrate these capabilities?

  1. ACloud Security Posture Management (CSPM)
  2. BSecurity Orchestration, Automation, and Response (SOAR)
  3. CSecurity Information and Event Management (SIEM)
  4. DCloud Access Security Broker (CASB)
Show answer & explanation

Correct answer: B. Security Orchestration, Automation, and Response (SOAR)

SOAR platforms are designed to integrate security tools, automate incident response workflows (playbooks), and orchestrate complex tasks, directly addressing the need to handle a high volume of alerts with automated responses.

Why the other options are wrong

  • A. CSPM focuses on identifying and remediating misconfigurations, not automating incident response.
  • C. SIEM collects, aggregates, and analyzes logs for alerts, but typically requires human intervention for response without SOAR.
  • D. CASB focuses on cloud service access, data governance, and threat protection for SaaS/PaaS, not automated incident response across the cloud.

Security Orchestration, Automation, and Response (SOAR)

A suite of software tools that helps organizations manage and respond to security incidents by orchestrating, automating, and streamlining security operations.

  • Automates repetitive security tasks and incident response workflows.
  • Integrates various security tools and platforms.
  • Improves incident response speed and consistency.

Memory trick: SOAR is your security's personal assistant: Orchestrates, Automates, Responds.

More Cloud Security questions