Question 1 of 30
A cybersecurity operations center (SOC) team is experiencing a significant surge in evasive, multi-stage attacks that bypass their existing perimeter defenses and signature-based intrusion detection systems. The current incident response playbook is largely manual and reactive, leading to prolonged detection and remediation times. The team\'s leadership recognizes the need for a fundamental shift in their security strategy to counter these advanced threats effectively. Which of the following strategic adjustments would best equip the SOC to adapt to this evolving threat landscape and improve its overall resilience?
Implement a Security Orchestration, Automation, and Response (SOAR) platform integrated with advanced threat intelligence feeds and behavioral analytics, enabling automated response actions and proactive threat hunting based on anomalous activity patterns.
Increase the frequency of vulnerability scans and penetration tests, and enhance the existing firewall rules with a broader range of known malicious IP addresses and domain blocklists.
Focus on enhancing endpoint detection and response (EDR) capabilities by deploying more agents and increasing the sampling rate for telemetry data collection without altering the core incident response workflow.
Reallocate budget to acquire more signature-based antivirus software licenses and invest in additional network intrusion prevention system (IPS) appliances to bolster existing detection layers.

Preparing for AWS Certified Security Specialty AWS Certified Security Specialty? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free