SOAR Playbook Development Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 SOAR Playbook Development flashcards as text
A SOC team wants to build a playbook for credential stuffing attacks. Which data source should be the PRIMARY trigger for this playbook?
Answer: Multiple failed login attempts followed by a successful login from an unusual geography
The pattern of repeated authentication failures followed by a suspicious successful login is a hallmark indicator of credential stuffing activity.
Which SOAR concept describes a reusable, modular unit of automation that can be called by multiple playbooks?
Answer: Sub-playbook or playbook block
Sub-playbooks encapsulate repeatable logic (e.g., IP enrichment, user deactivation) that can be invoked by many parent playbooks, reducing duplication.
During playbook testing, a security engineer discovers that an automated block action fires on internal IP addresses. What playbook control prevents this?
Answer: A pre-action allowlist or whitelist check that excludes RFC 1918 and trusted internal ranges
Allowlist checks before destructive actions ensure automation does not accidentally disrupt internal infrastructure or trusted assets.
What is the role of 'SLA timers' within a SOAR playbook for incident response?
Answer: To track response time against required targets and escalate if thresholds are exceeded
SLA timers enforce response-time commitments by escalating unresolved incidents to senior staff or management when deadlines approach.
A playbook designed for data exfiltration detection should include which containment action as a high-priority automated step?
Answer: Blocking the destination IP or domain at the firewall or proxy layer
Blocking the exfiltration destination at network controls is the most immediate containment action to stop active data loss.
Which metric best measures the operational effectiveness of a SOAR playbook over time?
Answer: Mean Time to Respond (MTTR) and the percentage of incidents handled without analyst intervention
MTTR reduction and automation rate directly reflect whether playbooks are speeding response and reducing manual workload as intended.
When documenting a SOAR playbook for compliance purposes, which element is MOST important to include for audit trails?
Answer: Timestamped logs of every automated and manual action taken during playbook execution
Detailed, timestamped action logs provide the evidence auditors need to verify that incident response followed documented procedures.