350-201 Question 240
Single answerAn organization has deployed a Security Orchestration, Automation, and Response (SOAR) platform to streamline its incident response process. During a recent phishing attack, the SOAR platform was used to automatically analyze email headers, extract malicious URLs, and block them on the firewall. Based on this scenario, which benefit of SOAR is being demonstrated?
- A
Threat intelligence sharing
- B
Incident response automation
- C
Security awareness training
- D
User behavior analysis
Show answer and explanation
Correct answer: B
Explanation
SOAR platforms are designed to automate repetitive security tasks and streamline incident response processes. In this scenario, the SOAR platform demonstrates incident response automation by analyzing email headers, extracting malicious URLs, and blocking them on the firewall without requiring manual intervention.
- A. Incorrect.
Threat intelligence sharing refers to the exchange of threat data between systems or organizations, which is not the focus in this scenario.
- B. Correct.
Incident response automation is correct because the SOAR platform is automating tasks such as email analysis, URL extraction, and firewall updates.
- C. Incorrect.
Security awareness training involves educating users on identifying and responding to security threats, which is unrelated to the automated processes described in the scenario.
- D. Incorrect.
User behavior analysis involves monitoring and analyzing user activities for anomalies, which is not part of this scenario.