exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 102 discussion

Actual exam question from CompTIA's CS0-003
Question #: 102
Topic #: 1
[All CS0-003 Questions]

An analyst recommends that an EDR agent collect the source IP address, make a connection to the firewall, and create a policy to block the malicious source IP address across the entire network automatically. Which of the following is the best option to help the analyst implement this recommendation?

  • A. SOAR
  • B. SIEM
  • C. SLA
  • D. IoC
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kmordalv
Highly Voted 1 year, 9 months ago
Selected Answer: A
Correct SOAR (Security Orchestration, Automation, and Response) is a technology that allows organizations to automate and streamline their security processes. It enables security teams to define and automate workflows, including tasks like threat detection, incident response, and remediation.
upvoted 5 times
...
king_basir88
Most Recent 7 months, 3 weeks ago
Last few questions regarding automation and/or minimal human interaction seems to be "SOAR".
upvoted 1 times
...
glenndexter
1 year, 2 months ago
The best option to help the analyst implement the recommendation is: A. SOAR (Security Orchestration, Automation, and Response) SOAR platforms are specifically designed to automate security operations, including tasks such as incident response, threat intelligence management, and workflow orchestration. By utilizing a SOAR platform, the analyst can create automated workflows that trigger actions based on events detected by the EDR agent, such as collecting the source IP address of a malicious connection. The SOAR platform can then integrate with the firewall to automatically create and enforce a policy to block the malicious IP address across the entire network. This approach streamlines the incident response process, reduces manual intervention, and improves the organization's overall security posture.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...