nerdexam
EC-Council

312-39 · Question #2

A Security Operations Center (SOC) analyst receives a high-priority alert indicating unusual user activity. An employee account is attempting to access company resources from a different country and…

The correct answer is B. Deprovisioning Users SOAR Playbook. When there is a strong indication of account compromise (impossible travel, unusual geography, out- of-hours access to sensitive resources), the priority is to reduce attacker dwell time by immediately restricting the account’s ability to authenticate and access data. A…

Security Incident Response

Question

A Security Operations Center (SOC) analyst receives a high-priority alert indicating unusual user activity. An employee account is attempting to access company resources from a different country and outside of their normal working hours. This behavior raises concerns about potential account compromise or unauthorized access. To automate the initial response and quickly restrict access while further investigating the incident, which SOAR playbook would be relevant to adapt and implement?

Options

  • AAlert Enrichment SOAR Playbook
  • BDeprovisioning Users SOAR Playbook
  • CMalware Containment SOAR Playbook
  • DPhishing Investigations SOAR Playbook

How the community answered

(39 responses)
  • A
    18% (7)
  • B
    69% (27)
  • C
    5% (2)
  • D
    8% (3)

Explanation

When there is a strong indication of account compromise (impossible travel, unusual geography, out- of-hours access to sensitive resources), the priority is to reduce attacker dwell time by immediately restricting the account’s ability to authenticate and access data. A “Deprovisioning Users” playbook aligns best with this objective because it is focused on access removal actions such as disabling the user, revoking active sessions, resetting credentials, invalidating refresh tokens, removing risky group memberships, and blocking sign-in until verification is complete. Alert enrichment is valuable, but it does not stop the threat; it only adds context. Malware containment is oriented toward endpoint isolation and malicious file/process containment, not identity-based risk. Phishing investigations is appropriate when the primary entry vector is suspected phishing and the goal is to analyze messages, URLs, and affected recipients, but it still may not provide the immediate identity lockdown needed. In SOC operations, identity compromise often demands rapid containment through account restriction first, followed by investigation to confirm legitimacy, determine scope, and safely restore access with stronger controls such as MFA and conditional access.

Topics

#SOAR playbook#account compromise#automated response#user deprovisioning

Community Discussion

No community discussion yet for this question.

Full 312-39 Practice