Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A security operations center (SOC) team is struggling to keep up with the volume of security alerts generated by their cloud environment. They need a solution that can automatically collect security data from various cloud services, correlate events, and execute predefined incident response playbooks without human intervention for common, low-risk incidents. Which cloud security technology would best integrate these capabilities?
- ACloud Security Posture Management (CSPM)
- BSecurity Orchestration, Automation, and Response (SOAR)
- CSecurity Information and Event Management (SIEM)
- DCloud Access Security Broker (CASB)
Show answer & explanationAnswer & explanation
Correct answer: B. Security Orchestration, Automation, and Response (SOAR)
SOAR platforms are designed to integrate security tools, automate incident response workflows (playbooks), and orchestrate complex tasks, directly addressing the need to handle a high volume of alerts with automated responses.
Why the other options are wrong
- A. CSPM focuses on identifying and remediating misconfigurations, not automating incident response.
- C. SIEM collects, aggregates, and analyzes logs for alerts, but typically requires human intervention for response without SOAR.
- D. CASB focuses on cloud service access, data governance, and threat protection for SaaS/PaaS, not automated incident response across the cloud.
Security Orchestration, Automation, and Response (SOAR)
A suite of software tools that helps organizations manage and respond to security incidents by orchestrating, automating, and streamlining security operations.
- Automates repetitive security tasks and incident response workflows.
- Integrates various security tools and platforms.
- Improves incident response speed and consistency.
Memory trick: SOAR is your security's personal assistant: Orchestrates, Automates, Responds.