SOAR Playbook Development Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 SOAR Playbook Development flashcards as text
A CCP candidate is reviewing a playbook that handles compromised service accounts. Which automated remediation step carries the highest risk if executed without human review?
Answer: Disabling the service account, potentially breaking dependent applications or services
Disabling a service account can immediately break production services that depend on it, making human review essential before this action is automated.
What is the purpose of a 'playbook kill switch' in SOAR operations?
Answer: To immediately pause or disable a running playbook if it is causing unintended damage or false positive actions
A kill switch provides operators a rapid way to halt a misbehaving playbook during an incident without waiting for a full platform change cycle.
During post-incident review, the team finds a SOAR playbook missed a key containment step for a lateral movement incident. What process should follow?
Answer: Conducting a lessons-learned review and updating the playbook logic to cover the missed scenario
Post-incident reviews translate gaps discovered in real incidents into playbook improvements, iteratively maturing the SOC's automated response capabilities.
Which threat intelligence standard is most commonly used to enrich SOAR playbook actions with structured indicator data?
Answer: STIX/TAXII (Structured Threat Information eXpression / Trusted Automated eXchange)
STIX defines the schema for threat intelligence objects (IOCs, TTPs) while TAXII provides the transport protocol, making them the standard for sharing threat intel with SOAR tools.
A playbook for cloud account compromise should include which cloud-specific automated action as an early containment step?
Answer: Revoking or rotating compromised IAM credentials and attaching a deny-all policy to the affected principal
Revoking or rotating IAM credentials and applying a deny-all policy immediately cuts off the attacker's access vector without destroying forensic evidence.
What distinguishes a SOAR 'playbook' from a traditional 'runbook' in a SOC context?
Answer: Playbooks are executed automatically by a SOAR platform with orchestration logic, while runbooks are manual step-by-step guides for analysts
Runbooks are human-executed procedural documents, whereas SOAR playbooks encode that logic as automated, machine-executable workflows with conditional branching.
A SOAR playbook for supply chain attack indicators should prioritize which initial automated action upon detecting a suspicious software update?
Answer: Isolating affected endpoints and blocking the update server's IP while awaiting threat intelligence confirmation
Isolating affected systems and blocking the update server limits spread while preserving forensics until threat intelligence confirms whether the update is malicious.