Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium

A large e-commerce platform processes millions of transactions daily. Due to increasing sophistication of cyber threats, the company wants to enhance its security operations to proactively identify and neutralize threats before they impact business. The cybersecurity architect is tasked with implementing a strategy that integrates threat intelligence, automates threat hunting, and orchestrates response actions across various security tools. Which of the following strategies is BEST suited for this purpose?

  1. AUtilizing a Data Loss Prevention (DLP) system with advanced content inspection.
  2. BEstablishing a robust Vulnerability Assessment and Penetration Testing (VAPT) program.
  3. CDeploying a Security Orchestration, Automation, and Response (SOAR) platform.
  4. DImplementing a comprehensive Endpoint Detection and Response (EDR) solution.
Show answer & explanation

Correct answer: C. Deploying a Security Orchestration, Automation, and Response (SOAR) platform.

A SOAR platform is specifically designed to integrate various security tools, automate incident response workflows, and orchestrate threat hunting activities based on enriched threat intelligence, directly addressing the company's requirements.

Why the other options are wrong

  • A. DLP prevents sensitive data exfiltration and does not address the broader need for integrating threat intelligence, automating threat hunting, and orchestrating responses.
  • B. VAPT is about identifying vulnerabilities in systems and applications, not about ongoing, automated threat hunting and response orchestration.
  • D. EDR focuses on endpoint activity monitoring and threat detection/response on individual devices, not enterprise-wide orchestration and automation.

Security Orchestration, Automation, and Response (SOAR)

SOAR platforms integrate security tools, automate incident response workflows, and orchestrate threat hunting and management tasks.

  • Automates repetitive security tasks.
  • Orchestrates complex incident response processes.
  • Enhances threat intelligence utilization.

Memory trick: SOAR is the 'Orchestra Conductor' of 'Security Automation' and 'Response'.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions