350-201 exam dumps

350-201 practice question 135 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 135

Select 3

A financial organization experiences frequent phishing attacks targeting its employees. The Security Operations Center (SOC) team wants to automate the response process to improve efficiency and reduce response time. Which procedural and SOAR workflows should be implemented to address this issue effectively?

  1. A

    Create an automated workflow to parse phishing emails and extract indicators of compromise (IOCs).

  2. B

    Escalate all phishing alerts directly to the SOC Tier 3 team for manual investigation.

  3. C

    Integrate the SOAR platform with the email gateway to automatically quarantine suspicious emails.

  4. D

    Develop a playbook to enrich IOCs using threat intelligence sources and automatically block malicious domains.

  5. E

    Route low-priority phishing alerts to a ticketing system for manual processing by the IT helpdesk.

Show answer and explanation

Correct answers: A, C, D

Explanation

To address phishing attacks efficiently, SOAR workflows must focus on automating tasks such as parsing emails, extracting IOCs, enriching data, and taking proactive actions like quarantining emails and blocking malicious domains. Escalating alerts or relying on manual processes is counterproductive and does not leverage the full potential of SOAR solutions.

  • A. Correct.

    Creating an automated workflow to parse phishing emails and extract IOCs is essential for quickly identifying threats without manual intervention. This is a key SOAR capability.

  • B. Incorrect.

    Escalating all phishing alerts directly to the SOC Tier 3 team increases workload and delays response times. Automation is preferred for initial triaging and response.

  • C. Correct.

    Integrating the SOAR platform with the email gateway allows for proactive action, such as quarantining suspicious emails, which reduces the risk of employee exposure to phishing attempts.

  • D. Correct.

    Enriching IOCs using threat intelligence and automatically blocking malicious domains ensures proactive mitigation of threats. This is a recommended SOAR workflow for phishing scenarios.

  • E. Incorrect.

    Routing low-priority phishing alerts to a ticketing system introduces delays and defeats the purpose of automating the response process.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam