nerdexam
Cisco

300-740 · Question #21

What must be automated to enhance the efficiency of a security team response?

The correct answer is C. Isolating affected systems and applying predefined security policies. Automating the isolation of affected systems and application of predefined security policies (C) is the gold standard because it contains threats immediately without human delay, limits lateral movement, and applies consistent, pre-approved responses - exactly what a Security…

Threat Response

Question

What must be automated to enhance the efficiency of a security team response?

Options

  • AChanging all user passwords when a threat is detected
  • BChanging firewall settings for every detected threat, regardless of its severity
  • CIsolating affected systems and applying predefined security policies
  • DSending an email to the entire organization when a threat is detected

How the community answered

(52 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    88% (46)
  • D
    4% (2)

Explanation

Automating the isolation of affected systems and application of predefined security policies (C) is the gold standard because it contains threats immediately without human delay, limits lateral movement, and applies consistent, pre-approved responses - exactly what a Security Orchestration, Automation, and Response (SOAR) system is designed to do.

Why the distractors fail:

  • A - Resetting all user passwords is a heavy-handed, disruptive action that doesn't target the actual threat and could cripple operations unnecessarily.
  • B - Changing firewall rules for every detected threat regardless of severity wastes resources and risks disrupting legitimate traffic for low-priority alerts (no triage = chaos).
  • D - Emailing the entire organization is a notification action, not a response action, and broadcasting threat details widely can cause panic or tip off malicious insiders.

Memory tip: Think "Contain first, notify smart." Effective automated response isolates the problem (C) rather than triggering broad, indiscriminate actions (A, B) or just broadcasting an alert (D). The word "predefined" in option C is your clue - good security automation uses pre-approved playbooks, not ad-hoc reactions.

Topics

#Incident response automation#Security policy enforcement#System isolation procedures#Threat response efficiency

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice