Automation & Incident Orchestration Flashcards
7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Automation & Incident Orchestration flashcards as text
What is 'alert deduplication' in automated incident management?
Answer: Grouping or suppressing repeated alerts about the same event to reduce noise and prevent duplicate tickets
Alert deduplication consolidates repeated alerts about the same underlying event, reducing noise and preventing analysts from working multiple tickets for a single incident.
In incident orchestration, what is the purpose of a 'dead letter queue'?
Answer: Capturing automation tasks or messages that fail to process so they can be reviewed and retried
A dead letter queue holds failed automation messages or tasks so they are not lost and can be investigated, retried, or manually handled.
A SOAR playbook must decide whether to auto-close an alert or escalate it. Which factor should most influence this decision logic?
Answer: A confidence score based on enrichment data such as threat intel reputation and asset criticality
Combining threat intelligence reputation and asset criticality into a confidence score gives the playbook objective, data-driven criteria for routing decisions.
What is 'runbook automation' and how does it differ from a full SOAR playbook?
Answer: Runbook automation executes predefined IT operational procedures step-by-step, while SOAR playbooks coordinate cross-tool security workflows with decision logic
Runbook automation focuses on standardized IT operational steps, whereas SOAR playbooks integrate multiple security tools, apply conditional logic, and manage the full incident lifecycle.
Which of the following best describes 'bi-directional integration' between a ticketing system and a SOAR platform?
Answer: Changes in either system—SOAR or the ticketing tool—are synchronized with the other in real time
Bi-directional integration ensures that status updates, comments, or field changes in either system are reflected in the other, keeping records consistent.
When automating the response to a ransomware incident, what action should the playbook prioritize FIRST?
Answer: Isolating affected hosts from the network to prevent lateral movement
Immediate network isolation of affected hosts is the top priority to prevent ransomware from spreading to additional systems before any recovery steps begin.
What is the significance of 'time-to-live' (TTL) values when automating threat intelligence indicator blocking in firewall rules?
Answer: TTL ensures that auto-added block rules expire after a set period, preventing stale rules from permanently blocking legitimate traffic
Setting a TTL on automatically added firewall block rules ensures they are removed after a defined period, reducing the risk of obsolete rules blocking legitimate traffic indefinitely.