nerdexam
CompTIA

SY0-701 · Question #334

Which of the following should a security operations center use to improve its incident response procedure?

The correct answer is A. Playbooks. A playbook is a documented set of procedures that outlines the step-by-step response to specific types of cybersecurity incidents. Security Operations Centers (SOCs) use playbooks to improve consistency, efficiency, and accuracy during incident response. Playbooks help ensure tha

Submitted by fernanda_arg· Mar 6, 2026Security Operations

Question

Which of the following should a security operations center use to improve its incident response procedure?

Options

  • APlaybooks
  • BFrameworks
  • CBaselines
  • DBenchmarks

How the community answered

(26 responses)
  • A
    88% (23)
  • B
    8% (2)
  • D
    4% (1)

Explanation

A playbook is a documented set of procedures that outlines the step-by-step response to specific types of cybersecurity incidents. Security Operations Centers (SOCs) use playbooks to improve consistency, efficiency, and accuracy during incident response. Playbooks help ensure that the correct procedures are followed based on the type of incident, ensuring swift and effective Frameworks provide general guidelines for implementing security but are not specific enough for incident response procedures. Baselines represent normal system behavior and are used for anomaly detection, not incident response guidance. Benchmarks are performance standards and are not directly related to incident response.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice