CAS-005 · Question #158
A company currently uses manual processes to regularly address incidents occurring outside of working hours. Hiring or implementing a SOC is not an option because of budget limitations. Which of the…
The correct answer is D. Design proper runbooks and implement security orchestration and automation with integrated. Without a SOC and facing budget limitations for staffing, the company needs an automated solution to handle incident response processes outside of working hours effectively.
Question
A company currently uses manual processes to regularly address incidents occurring outside of working hours. Hiring or implementing a SOC is not an option because of budget limitations. Which of the following solutions would most likely decrease the current risk?
Options
- AImprove logging capabilities, integrating those logs with the existing SIEM and creating better
- BImplement a NIPS integrated with the firewall, raising new rules to block any malicious access
- CEvaluate and implement new endpoint security tools, helping to prevent attack attempts.
- DDesign proper runbooks and implement security orchestration and automation with integrated
How the community answered
(17 responses)- A6% (1)
- B6% (1)
- C12% (2)
- D76% (13)
Why each option
Without a SOC and facing budget limitations for staffing, the company needs an automated solution to handle incident response processes outside of working hours effectively.
Improving logging and SIEM integration is crucial for detection but does not inherently automate the *response* to incidents occurring outside working hours, still requiring human intervention.
Implementing a Network Intrusion Prevention System (NIPS) integrated with a firewall can block some malicious access, but it is a preventative measure, not a comprehensive solution for *incident response* to various types of incidents.
Implementing new endpoint security tools enhances prevention, detection, and response capabilities at the endpoint, but similar to NIPS, it's a component of security, not a holistic solution for automating *incident management* processes.
Designing proper runbooks provides standardized procedures, and implementing Security Orchestration, Automation, and Response (SOAR) automates these procedures, allowing for rapid and consistent response to incidents even outside working hours. This directly addresses the challenge of managing incidents without human staff availability, reducing risk by ensuring timely actions.
Concept tested: Security Orchestration, Automation, and Response
Source: https://learn.microsoft.com/en-us/azure/sentinel/automation-logic-apps-playbooks
Community Discussion
No community discussion yet for this question.