← All CIM Flashcard Decks

Automation & Incident Orchestration Flashcards

7 cards from real CIM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Automation & Incident Orchestration flashcards as text
  1. What is 'alert deduplication' in automated incident management?

    Answer: Grouping or suppressing repeated alerts about the same event to reduce noise and prevent duplicate tickets

    Alert deduplication consolidates repeated alerts about the same underlying event, reducing noise and preventing analysts from working multiple tickets for a single incident.

  2. In incident orchestration, what is the purpose of a 'dead letter queue'?

    Answer: Capturing automation tasks or messages that fail to process so they can be reviewed and retried

    A dead letter queue holds failed automation messages or tasks so they are not lost and can be investigated, retried, or manually handled.

  3. A SOAR playbook must decide whether to auto-close an alert or escalate it. Which factor should most influence this decision logic?

    Answer: A confidence score based on enrichment data such as threat intel reputation and asset criticality

    Combining threat intelligence reputation and asset criticality into a confidence score gives the playbook objective, data-driven criteria for routing decisions.

  4. What is 'runbook automation' and how does it differ from a full SOAR playbook?

    Answer: Runbook automation executes predefined IT operational procedures step-by-step, while SOAR playbooks coordinate cross-tool security workflows with decision logic

    Runbook automation focuses on standardized IT operational steps, whereas SOAR playbooks integrate multiple security tools, apply conditional logic, and manage the full incident lifecycle.

  5. Which of the following best describes 'bi-directional integration' between a ticketing system and a SOAR platform?

    Answer: Changes in either system—SOAR or the ticketing tool—are synchronized with the other in real time

    Bi-directional integration ensures that status updates, comments, or field changes in either system are reflected in the other, keeping records consistent.

  6. When automating the response to a ransomware incident, what action should the playbook prioritize FIRST?

    Answer: Isolating affected hosts from the network to prevent lateral movement

    Immediate network isolation of affected hosts is the top priority to prevent ransomware from spreading to additional systems before any recovery steps begin.

  7. What is the significance of 'time-to-live' (TTL) values when automating threat intelligence indicator blocking in firewall rules?

    Answer: TTL ensures that auto-added block rules expire after a set period, preventing stale rules from permanently blocking legitimate traffic

    Setting a TTL on automatically added firewall block rules ensures they are removed after a defined period, reducing the risk of obsolete rules blocking legitimate traffic indefinitely.