Automation & Incident Orchestration Flashcards
7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Automation & Incident Orchestration flashcards as text
What is the primary risk of over-automating incident response without adequate tuning?
Answer: High false-positive rates causing alert fatigue and unintended automated actions
Poorly tuned automation can act on false positives, triggering unnecessary responses that disrupt services or waste resources, worsening analyst workload.
In SOAR-driven incident orchestration, what is the role of a 'connector' or 'integration'?
Answer: A software component that enables the SOAR platform to communicate with external tools such as firewalls or SIEMs
Connectors/integrations are adapters that allow SOAR platforms to authenticate and exchange data with third-party security tools through their APIs.
Which approach best supports continuous improvement of automated incident playbooks?
Answer: Reviewing playbook execution metrics and post-incident feedback to iteratively refine logic
Regular review of execution metrics and lessons learned from incidents allows teams to identify gaps and optimize playbook logic over time.
An automated playbook quarantines an endpoint immediately upon detecting malware. What critical step should the playbook also trigger simultaneously?
Answer: Notify the endpoint owner and create an incident ticket for analyst follow-up
Simultaneous notification and ticket creation ensures analysts are aware of the automated action and can investigate root cause and impact without delay.
What distinguishes 'orchestration' from 'automation' in the context of incident response?
Answer: Orchestration coordinates multiple automated tasks and tools across a workflow, while automation refers to individual task execution
Orchestration manages the sequencing, coordination, and decision logic across multiple automated steps and disparate tools, whereas automation executes a single repeatable task.
Why is version control important for incident response playbooks in a SOAR environment?
Answer: It tracks changes over time, allows rollback to known-good versions, and supports auditability
Version control provides a history of playbook changes, enables rollback when a new version introduces errors, and satisfies audit requirements for change management.
A security team wants to automate phishing email response. Which sequence of playbook steps is most logical?
Answer: Extract IOCs → Block sender/URL → Search mailboxes for similar emails → Notify affected users
Extracting IOCs first enables all subsequent blocking and hunting steps to be targeted, making the response both systematic and thorough.