nerdexam
Splunk

SPLK-5001 · Question #54

How are SOAR playbooks used in threat hunting?

The correct answer is C. To automate response actions based on specific security scenarios. SOAR (Security Orchestration, Automation, and Response) playbooks are predefined workflows that automate response actions when specific security conditions are met - making C correct. They orchestrate tools and tasks (e.g., isolate a host, send an alert, block an IP) in…

Threat Detection and Alerting

Question

How are SOAR playbooks used in threat hunting?

Options

  • ATo define and test hypotheses related to security incidents.
  • BTo monitor the network for anomalies and indicators of compromise.
  • CTo automate response actions based on specific security scenarios.
  • DTo analyze historical data for patterns of abnormal behavior.

How the community answered

(45 responses)
  • A
    7% (3)
  • B
    4% (2)
  • C
    87% (39)
  • D
    2% (1)

Explanation

SOAR (Security Orchestration, Automation, and Response) playbooks are predefined workflows that automate response actions when specific security conditions are met - making C correct. They orchestrate tools and tasks (e.g., isolate a host, send an alert, block an IP) in response to detected scenarios, reducing manual effort and response time.

  • A is wrong because defining and testing hypotheses is the core of threat hunting methodology, not SOAR playbooks - that's an analyst-driven, iterative process.
  • B is wrong because network anomaly and IoC monitoring is the job of SIEM/IDS/NDR tools, not SOAR playbooks.
  • D is wrong because analyzing historical data for behavioral patterns describes User and Entity Behavior Analytics (UEBA) or forensic analysis, not SOAR functionality.

Memory tip: Think of SOAR playbooks as a "recipe book for robots" - when condition X happens, the robot (automation) follows the recipe (playbook) and acts. If it's about detecting or analyzing, it's not SOAR's primary role.

Topics

#SOAR playbooks#threat hunting#automated response#security automation

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice