nerdexam
CompTIA

CAS-005 · Question #158

A company currently uses manual processes to regularly address incidents occurring outside of working hours. Hiring or implementing a SOC is not an option because of budget limitations. Which of the…

The correct answer is D. Design proper runbooks and implement security orchestration and automation with integrated. Without a SOC and facing budget limitations for staffing, the company needs an automated solution to handle incident response processes outside of working hours effectively.

Submitted by andres_qro· Mar 6, 2026Security Operations

Question

A company currently uses manual processes to regularly address incidents occurring outside of working hours. Hiring or implementing a SOC is not an option because of budget limitations. Which of the following solutions would most likely decrease the current risk?

Options

  • AImprove logging capabilities, integrating those logs with the existing SIEM and creating better
  • BImplement a NIPS integrated with the firewall, raising new rules to block any malicious access
  • CEvaluate and implement new endpoint security tools, helping to prevent attack attempts.
  • DDesign proper runbooks and implement security orchestration and automation with integrated

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    12% (2)
  • D
    76% (13)

Why each option

Without a SOC and facing budget limitations for staffing, the company needs an automated solution to handle incident response processes outside of working hours effectively.

AImprove logging capabilities, integrating those logs with the existing SIEM and creating better

Improving logging and SIEM integration is crucial for detection but does not inherently automate the *response* to incidents occurring outside working hours, still requiring human intervention.

BImplement a NIPS integrated with the firewall, raising new rules to block any malicious access

Implementing a Network Intrusion Prevention System (NIPS) integrated with a firewall can block some malicious access, but it is a preventative measure, not a comprehensive solution for *incident response* to various types of incidents.

CEvaluate and implement new endpoint security tools, helping to prevent attack attempts.

Implementing new endpoint security tools enhances prevention, detection, and response capabilities at the endpoint, but similar to NIPS, it's a component of security, not a holistic solution for automating *incident management* processes.

DDesign proper runbooks and implement security orchestration and automation with integratedCorrect

Designing proper runbooks provides standardized procedures, and implementing Security Orchestration, Automation, and Response (SOAR) automates these procedures, allowing for rapid and consistent response to incidents even outside working hours. This directly addresses the challenge of managing incidents without human staff availability, reducing risk by ensuring timely actions.

Concept tested: Security Orchestration, Automation, and Response

Source: https://learn.microsoft.com/en-us/azure/sentinel/automation-logic-apps-playbooks

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice