Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A large healthcare provider is migrating sensitive patient data to a hybrid cloud environment. The cybersecurity architect needs to ensure that the organization can demonstrate continuous compliance with HIPAA and GDPR regulations, particularly regarding data access and audit trails. They are evaluating strategies for security operations. Which strategy provides the most effective balance between automated compliance validation and human oversight for critical incidents?

  1. ASolely relying on manual review of SIEM alerts by a dedicated security operations center (SOC) team.
  2. BImplementing an SOAR platform integrated with a SIEM, leveraging playbooks for automated responses to common incidents, while escalating critical or unknown threats to human analysts.
  3. CFull automation of all security incident responses without human intervention to maximize efficiency.
  4. DOutsourcing all security operations to a managed security service provider (MSSP) without internal oversight.
Show answer & explanation

Correct answer: B. Implementing an SOAR platform integrated with a SIEM, leveraging playbooks for automated responses to common incidents, while escalating critical or unknown threats to human analysts.

Integrating SOAR with SIEM allows for automated handling of routine incidents, significantly improving efficiency, while ensuring that complex or high-priority threats receive expert human analysis and decision-making. This hybrid approach optimizes both speed and accuracy for GRC in a sensitive environment.

Why the other options are wrong

  • A. Solely manual review is inefficient and prone to alert fatigue, making it difficult to maintain continuous compliance and respond quickly to high-volume threats.
  • C. Full automation without human oversight is risky for sensitive healthcare data, as it may lead to incorrect responses or missed nuances in critical incidents, violating compliance requirements.
  • D. While MSSPs can augment security, complete outsourcing without internal oversight risks losing institutional knowledge and control, which is critical for compliance with regulations like HIPAA and GDPR.

SOAR (Security Orchestration, Automation, and Response)

SOAR platforms automate and orchestrate security operations tasks, incident response workflows, and threat intelligence management.

  • Reduces manual effort and response times for security incidents.
  • Integrates with various security tools (e.g., SIEM, firewalls).
  • Enables consistent and repeatable incident response processes.

Memory trick: Automated Response Needs Human Oversight

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions