SY0-701 exam dumps

SY0-701 practice question 376 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 376

Single answer4.7 Explain the importance of automation and orchestration related to secure operations.

A security operations center (SOC) is overwhelmed by repeated phishing emails that deliver the same malicious attachment to multiple users each day. Analysts currently review alerts manually, block hashes by hand, and open tickets for endpoint isolation when malware is detected. The security manager wants to reduce response time and improve consistency without giving up human oversight for high-impact actions. Which solution BEST meets this requirement?

  1. A

    Deploy a SOAR platform that automatically enriches phishing alerts, correlates indicators across email and endpoint tools, and requires analyst approval before isolating affected hosts

  2. B

    Replace the SIEM with a vulnerability scanner so phishing campaigns can be detected through weekly authenticated scans

  3. C

    Disable email security filtering and have users forward suspicious messages to the SOC for manual review to reduce false positives

  4. D

    Implement a NAC solution that permanently blocks any device that receives an email attachment

Show answer and explanation

Correct answer: A

Explanation

The best answer is the SOAR-based workflow because the topic focuses on the importance of automation and orchestration in secure operations. Automation handles repetitive, well-defined tasks such as alert enrichment, indicator extraction, ticket creation, and initiating playbooks. Orchestration coordinates actions across different security technologies so the SOC can respond faster and more consistently. In real environments, best practice is to automate low-risk, repeatable steps while retaining human approval for disruptive actions like host isolation or account disablement. This aligns with common guidance from vendors and industry frameworks that emphasize reducing analyst fatigue, improving repeatability, and shortening mean time to detect and respond through integrated playbooks and approval gates.

  • A. Correct.

    Correct. A SOAR platform is designed to automate and orchestrate security workflows across multiple tools, such as email security gateways, EDR, SIEM, and ticketing systems. In this scenario, it can automatically enrich phishing alerts with threat intelligence, extract and compare file hashes and URLs, create tickets, and coordinate response steps. Requiring analyst approval before host isolation preserves human decision-making for high-impact actions while still reducing mean time to respond and improving consistency.

  • B. Incorrect.

    Incorrect. A vulnerability scanner identifies missing patches, configuration weaknesses, and exposed services; it is not the primary tool for detecting and responding to phishing campaigns in near real time. Replacing a SIEM with a vulnerability scanner would reduce detection and correlation capability rather than improve secure operations automation.

  • C. Incorrect.

    Incorrect. Disabling email security filtering would increase risk by allowing more malicious content to reach users. Although manual reporting by users can supplement phishing detection, it is not an automation or orchestration improvement and would likely increase analyst workload instead of reducing it.

  • D. Incorrect.

    Incorrect. NAC can control network access based on policy, posture, or identity, but permanently blocking any device that merely receives an attachment is overly broad and not aligned with the scenario. Receipt of an attachment does not prove compromise. This option also lacks the needed orchestration and human approval workflow.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam