Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A security analyst is investigating a potential data exfiltration attempt from a cloud storage bucket. The incident response plan requires immediate notification to the security team and automated blocking of the suspicious IP address at the network edge. Which cloud security automation and orchestration component is responsible for triggering predefined actions based on security events?
- ACloud Access Security Broker (CASB)
- BCloud Security Posture Management (CSPM)
- CSecurity Orchestration, Automation, and Response (SOAR)
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: C. Security Orchestration, Automation, and Response (SOAR)
SOAR (Security Orchestration, Automation, and Response) platforms are designed to collect security alerts, orchestrate human and machine responses, and automate actions like blocking IP addresses or notifying teams. This directly matches the requirement for triggering predefined actions based on security events.
Why the other options are wrong
- A. CASB focuses on securing cloud application usage and data, not on orchestrating and automating incident response across the broader cloud environment.
- B. CSPM focuses on identifying and remediating misconfigurations, not on automated incident response actions for active threats.
- D. SIEM aggregates and analyzes security events but typically doesn't automate response actions directly without integration with other tools.
SOAR (Security Orchestration, Automation, and Response)
A platform that helps automate and orchestrate security operations tasks, incident response, and threat management.
- Automates repetitive security tasks.
- Orchestrates workflows across multiple security tools.
- Facilitates faster incident response.
Memory trick: SOAR: Soaring above incidents with Automated Responses.