exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 226 discussion

Actual exam question from CompTIA's SY0-601
Question #: 226
Topic #: 1
[All SY0-601 Questions]

A recent phishing campaign resulted in several compromised user accounts. The security incident response team has been tasked with reducing the manual labor of filtering through all the phishing emails as they arrive and blocking the sender’s email address, along with other time-consuming mitigation actions. Which of the following can be configured to streamline those tasks?

  • A. SOAR playbook
  • B. MDM policy
  • C. Firewall rules
  • D. URL filter
  • E. SIEM data collection
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Kashim
Highly Voted 2 years, 7 months ago
Selected Answer: A
Automation = SOAR playbook
upvoted 13 times
...
sujon_london
Most Recent 1 year, 8 months ago
Selected Answer: A
SOAR is the solution in terms of automation with reducing less labor.
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 9 months ago
Selected Answer: A
A Security Orchestration, Automation, and Response (SOAR) playbook can be configured to streamline the tasks of filtering through phishing emails, blocking sender email addresses, and automating other mitigation actions. SOAR platforms are designed to help security teams automate and orchestrate incident response processes, making incident handling more efficient and less labor-intensive. In the context of a phishing campaign, a SOAR playbook can be created to automatically analyze incoming emails for phishing indicators, such as suspicious URLs or attachments, and trigger specific actions based on predefined rules. For example, the playbook can automatically block the sender's email address, quarantine suspicious emails, notify relevant stakeholders, and initiate the investigation process. By leveraging automation and orchestration through a SOAR platform, the incident response team can significantly reduce the manual effort required to handle phishing incidents and respond to them more effectively and efficiently.
upvoted 3 times
...
LeonardSnart
1 year, 11 months ago
Selected Answer: A
"As a simple example, SOAR tools can examine and respond to phishing emails, reducing the amount of time needed by personnel to investigate them. By looking at email elements, such as the header, embedded URLs, and attachments, it’s possible to detect suspicious emails. These can be forwarded to other tools to investigate further. For example, a SOAR tool can open attachments within a sandbox and observe the activity. Another SOAR tool may dissect the header looking for discrepancies common in phishing emails such as spoofed email addresses. When the SOAR platform verifies an email is malicious, it can automatically respond. The response is dependent on the organization’s available tools and internal guidelines. It may include quarantining or deleting the email and blocking access to the embedded URLs." -Security+ Get Certified Get Ahead SY0-601 Study Guide by Darril Gibson
upvoted 1 times
...
carpathia
2 years, 5 months ago
Selected Answer: A
https://securityboulevard.com/2021/02/your-first-soar-use-case-phishing-triage/
upvoted 2 times
...
rodwave
2 years, 5 months ago
Selected Answer: A
Answer: SOAR playbook SOAR playbooks are used to automate key functions of a SOC based on processes documented in the incident response playbooks.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago