300-220 · Question #85
What are the advantages of using automation in the operation of a SOC? (Choose two)
The correct answer is A. Reduces the need for human intervention D. Enhances the ability to detect complex threats. Automation in a SOC reduces the need for human intervention (A) by handling repetitive tasks like log parsing, alert triage, and routine responses - freeing analysts for higher-order work. It also enhances detection of complex threats (D) by enabling continuous, high-speed…
Question
What are the advantages of using automation in the operation of a SOC? (Choose two)
Options
- AReduces the need for human intervention
- BIncreases the time to detect and respond to incidents
- CDecreases false positive rates
- DEnhances the ability to detect complex threats
How the community answered
(31 responses)- A94% (29)
- B3% (1)
- C3% (1)
Explanation
Automation in a SOC reduces the need for human intervention (A) by handling repetitive tasks like log parsing, alert triage, and routine responses - freeing analysts for higher-order work. It also enhances detection of complex threats (D) by enabling continuous, high-speed correlation of vast datasets that humans alone couldn't process at scale, such as behavioral anomalies or multi-stage attack patterns.
Why B is wrong: Automation decreases detection and response time (MTTD/MTTR), not increases it - faster processing is one of its primary benefits.
Why C is wrong: Automation can actually increase false positives if rules are poorly tuned; it doesn't inherently decrease them. Reducing false positives requires careful tuning and threat intelligence integration, not automation itself.
Memory tip: Think "AID" - Automation Augments analysts and Improves Detection. If an answer says automation slows things down or fixes false positives by default, it's a trap.
Topics
Community Discussion
No community discussion yet for this question.