Question 1 of 30
In a security operations center (SOC), an analyst is tasked with automating the incident response process for a series of phishing attacks targeting employees. The automation tool must integrate with existing security information and event management (SIEM) systems and utilize threat intelligence feeds to enhance its effectiveness. Which approach should the analyst prioritize to ensure the automation process is both efficient and effective in mitigating these phishing threats?
Implement a playbook that includes automated alerts, predefined response actions, and integration with threat intelligence to enrich incident data.
Focus solely on automating the alert generation process without predefined response actions to allow for human intervention.
Develop a manual process for incident response that relies on human analysis to determine the severity of each phishing attempt.
Use a single threat intelligence feed to inform the automation process, disregarding the need for multiple sources of information.

Preparing for CISCO 350-701 Implementing and Operating Cisco Security Core Technologies (SCOR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free