exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 174 discussion

Actual exam question from CompTIA's CS0-002
Question #: 174
Topic #: 1
[All CS0-002 Questions]

Which of the following is an advantage of SOAR over SIEM?

  • A. SOAR is much less expensive.
  • B. SOAR reduces the amount of human intervention required.
  • C. SOAR can aggregate data from many sources.
  • D. SOAR uses more robust encryption protocols.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kumax
1 year, 7 months ago
Selected Answer: B
SOAR: Security Orchestration, Automation, and Response
upvoted 1 times
...
Kickuh06
1 year, 9 months ago
Selected Answer: B
Key Word: Automation.
upvoted 1 times
...
R00ted
2 years, 7 months ago
Selected Answer: C
gement tools. SOAR systems and services tend to add a layer of workflow management. That means that SOAR deployments may actually ingest SIEM alerts and other data and then apply workflows and automation to them. SIEM and SOAR tools can be difficult to distinguish from each other, with one current difference being the broader range of tools that SOAR services integrate with. The same vendors who provide SIEM capabilities also provide SOAR systems in many cases with Splunk, Rapid7, and IBM (QRadar) all included. There are differences, however, as ITSM tools like ServiceNow play in the space as well. As an analyst, you need to know that SOAR services and tools exist and can be leveraged to cover additional elements beyond what traditional SIEM systems have historically handled.
upvoted 1 times
SolventCourseisSCAM
2 years, 6 months ago
Answer is B without doubt.
upvoted 2 times
...
Adrian831
2 years, 7 months ago
When comparing SOAR vs. SIEM, SIEM will only provide the alert. After that, it's up to the administrator to determine the path of an investigation (so, this means in my opinion more human intervation). A SOAR that automates investigation path workflows can significantly cut down on the amount of time required to handle alerts.
upvoted 7 times
R00ted
2 years, 7 months ago
Good point. I am changing my answer to B
upvoted 3 times
...
2Fish
2 years, 1 month ago
Agreed. Thank you for the explanation.
upvoted 1 times
...
...
...
Tag
2 years, 7 months ago
Selected Answer: B
definitely B
upvoted 1 times
...
Adrian831
2 years, 7 months ago
Selected Answer: B
B seems right
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago