exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 275 discussion

Actual exam question from CompTIA's CS0-002
Question #: 275
Topic #: 1
[All CS0-002 Questions]

A security team is struggling with alert fatigue, and the Chief Information Security Officer has decided to purchase a SOAR platform to alleviate this issue. Which of the following BEST describes how a SOAR platform will help the security team?

  • A. SOAR will integrate threat intelligence into the alerts, which will help the security team decide which events should be investigated first.
  • B. A SOAR platform connects the SOC with the asset database, enabling the security team to make informed decisions immediately based on asset criticality.
  • C. The security team will be able to use the SOAR framework to integrate the SIEM with a TAXII server, which has an automated intelligence feed that will enhance the alert data.
  • D. Logic can now be created that will allow the SOAR platform to block specific traffic at the firewall according to predefined event triggers and actions.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ZUL01
Highly Voted 2 years, 1 month ago
Under this link "https://www.sirp.io/blog/how-soar-helps-security-teams-fight-alert-fatigue/", we can find that both A and D options are valid. Well congrats comptia for creating so sophisticated questions.
upvoted 15 times
...
Stiobhan
Highly Voted 2 years, 3 months ago
Selected Answer: D
For those that put A, how does this reduce alert fatigue? The solution might do some triaging for you but it still requires the alert to be actioned.
upvoted 6 times
HereToStudy
2 years, 2 months ago
Threat intelligence can reduce the number of false positives which helps with alert fatigue
upvoted 1 times
...
2Fish
2 years, 2 months ago
Hmmm.. I did originally think A, you do make a good point. Automation can technically relieve alert fatigue and allow the analyst to concentrate on other critical issues.
upvoted 2 times
...
...
zecomeia_007
Most Recent 1 year ago
Selected Answer: A
A SOAR will integrate threat intelligence into the alerts, which will help the security team decide which events should be investigated first.
upvoted 1 times
...
Chilaqui1es
1 year, 7 months ago
Another time wasting question... D sounds like a better option because it would reduce alerts which seems to be the goal here rather than A which prioritizes alerts.
upvoted 1 times
...
Bubu3k
1 year, 10 months ago
Selected Answer: D
I see lots of A...as per chat GPT, lol. That would be a valid answer but in the end, you'd still have the same number of alerts, but less stress figuring out which ones to work on. However, I would go with, if part of the problems "solve themselves" via automation means fewer overall alerts = a happy team lol
upvoted 1 times
...
johndoe69
1 year, 10 months ago
Selected Answer: D
SOAR can automatically take action on firewalls based on specified use cases. I work in a SOC for an MSSP and we use SOAR for some of our clients. Answer is D.
upvoted 1 times
...
Dany_Suarez
1 year, 11 months ago
Selected Answer: A
kiduuu is right!
upvoted 1 times
...
kiduuu
2 years, 1 month ago
Selected Answer: A
SOAR platform can help the security team prioritize alerts by integrating threat intelligence into the alerts. By doing so, the platform can help the security team decide which events should be investigated first, reducing alert fatigue and enabling faster response times to potential threats. Option D describes how a SOAR platform can create logic to block specific traffic at the firewall, but it is not directly related to addressing alert fatigue.
upvoted 1 times
...
thenewpcgamer
2 years, 1 month ago
Selected Answer: A
I can not find any reference on google that allows a SOAR system to implement firewall changes, Therefore I must go with A.
upvoted 1 times
...
HereToStudy
2 years, 2 months ago
Selected Answer: A
As stated bellow threat intelligence can reduce the number of false positives
upvoted 1 times
...
Kashim
2 years, 3 months ago
Selected Answer: D
A SOAR (Security Orchestration, Automation, and Response) platform will help the security team by automating the response to alerts, reducing the time required for manual investigation and response. The platform can perform automated actions based on predefined rules and workflows, reducing the workload of security analysts and improving the efficiency of incident response. This can significantly reduce alert fatigue and enable security teams to focus on more critical tasks. Therefore, option D, which describes the use of logic to block specific traffic at the firewall based on predefined event triggers and actions, is the BEST description of how a SOAR platform will help the security team.
upvoted 4 times
...
talosDevbot
2 years, 3 months ago
Selected Answer: A
From PaloAlto's website about SOARs: Integrate security, IT operations and threat intelligence tools. You can connect all your different security solutions - even tools from different vendors - to achieve a more comprehensive level of data collection and analysis. Security teams can stop juggling a variety of different consoles and tools.
upvoted 2 times
2Fish
2 years, 3 months ago
Agree. A SOAR will absolutely help with the fatigue.
upvoted 1 times
...
...
Farzananazy
2 years, 4 months ago
Selected Answer: A
i agree with A
upvoted 1 times
...
db97
2 years, 4 months ago
Why D? Where in the questions says that the fatigue is due firewall alerts? And also, the firewall thing is not the only capability that a SOAR has. Going with A here.
upvoted 1 times
...
encxorblood
2 years, 4 months ago
Selected Answer: A
A SOAR (Security Orchestration, Automation, and Response) platform will help the security team by option A, integrating threat intelligence into the alerts, which will help the security team decide which events should be investigated first. A SOAR platform is designed to streamline the incident response process by integrating and automating the various security tools used by the security team. One of the key features of a SOAR platform is its ability to integrate threat intelligence feeds into the alerts generated by security tools, such as a SIEM (Security Information and Event Management) system. By integrating threat intelligence into the alerts, a SOAR platform can help the security team to quickly identify which alerts are the most critical and require immediate attention.
upvoted 2 times
...
PhillyCheese
2 years, 4 months ago
Selected Answer: D
Security orchestration, automation, and response (SOAR) refers to a set of services and tools that automate cyberattack prevention and response. This automation is accomplished by unifying your integrations, defining how tasks should be run, and developing an incident response plan that suits your organization’s needs. A and B don't touch on the benefits of automation.
upvoted 2 times
talosDevbot
2 years, 3 months ago
Option D only addresses incidents involving traffic through the firewall. How about alerts that are just in the internal network? Issue here is alert fatigue. Integrating threat intelligence can reduce false positive
upvoted 2 times
...
...
chuck165
2 years, 4 months ago
Selected Answer: D
SOAR A= Automation = less alerts to look at by automating the response.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...