nerdexam
CompTIA

CS0-003 · Question #509

A newly hired security manager in a SOC wants to improve efficiency by automating routine tasks. Which of the following SOC tasks is most suitable for automation?

The correct answer is D. Generating incident reports and notifying the appropriate stakeholders. Generating incident reports and notifying stakeholders is a highly structured, repeatable task, making it the most suitable SOC activity for automation to improve efficiency.

Submitted by priya_blr· Mar 6, 2026Security Operations

Question

A newly hired security manager in a SOC wants to improve efficiency by automating routine tasks. Which of the following SOC tasks is most suitable for automation?

Options

  • AConducting security assessments and audits of IT systems
  • BInvestigating security incidents and determining the root causes
  • CReviewing logs and alerts to identify security threats and anomalies
  • DGenerating incident reports and notifying the appropriate stakeholders

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    4% (1)
  • D
    79% (19)

Why each option

Generating incident reports and notifying stakeholders is a highly structured, repeatable task, making it the most suitable SOC activity for automation to improve efficiency.

AConducting security assessments and audits of IT systems

Conducting security assessments and audits requires critical thinking, contextual understanding, and often manual verification that is difficult to fully automate.

BInvestigating security incidents and determining the root causes

Investigating security incidents and determining root causes involves complex analysis, hypothesis testing, and human judgment, which are generally not suitable for full automation.

CReviewing logs and alerts to identify security threats and anomalies

While initial filtering and correlation of logs and alerts can be automated, the actual review and identification of subtle security threats and anomalies often require human expertise and contextual understanding beyond simple automation.

DGenerating incident reports and notifying the appropriate stakeholdersCorrect

Generating incident reports and notifying stakeholders involves gathering specific data, formatting it into a report, and dispatching it to a predefined list of recipients, often based on incident type or severity. This task is highly structured and repetitive, making it an excellent candidate for automation through scripting or Security Orchestration, Automation, and Response (SOAR) platforms to improve efficiency and reduce manual effort.

Concept tested: SOC task automation suitability

Source: https://learn.microsoft.com/en-us/azure/sentinel/automation-logic-apps-playbooks

Topics

#SOC automation#SOAR#incident reporting#workflow automation

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice