Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 100-160 Exam - Topic 1 Question 3 Discussion

You need a software solution that performs the following tasks:Compiles network dataLogs information from many sourcesProvides orchestration in the form of case managementAutomates incident response workflowsWhat product should you use?
B) SOAR
A) SIEM
C) NextGen IPS
D) Snort

Cisco 100-160 Exam - Topic 1 Question 3 Discussion

Actual exam question for Cisco's 100-160 exam
Question #: 3
Topic #: 1
[All 100-160 Questions]

You need a software solution that performs the following tasks:

Compiles network data

Logs information from many sources

Provides orchestration in the form of case management

Automates incident response workflows

What product should you use?

Show Suggested Answer Hide Answer
Suggested Answer: B

The CCST Cybersecurity Study Guide explains that SOAR (Security Orchestration, Automation, and Response) platforms integrate data from multiple tools and sources, support case management, and automate security workflows for faster incident response.

'SOAR solutions provide orchestration, automation, and response capabilities. They collect security data from multiple systems, enable analysts to manage incidents, and automate repetitive tasks in the response process.'

(CCST Cybersecurity, Incident Handling, Security Automation Tools section, Cisco Networking Academy)

A (SIEM) collects and correlates security logs but lacks full orchestration and automated response capabilities.

B is correct: SOAR adds orchestration, case management, and automated incident response.

C (NextGen IPS) focuses on intrusion prevention, not orchestration.

D (Snort) is an open-source intrusion detection/prevention tool, not an orchestration platform.


Contribute your Thoughts:

0/2000 characters
Rachael
8 months ago
Snort is great, but it doesn't do case management like the others.
upvoted 0 times
...
Noemi
8 months ago
Wait, can SOAR really handle all those tasks?
upvoted 0 times
...
Jolanda
8 months ago
I think SOAR is the better choice for automation!
upvoted 0 times
...
Juan
9 months ago
NextGen IPS is more about prevention, not orchestration.
upvoted 0 times
...
Amber
9 months ago
Definitely a SIEM for logging and data compilation.
upvoted 0 times
...
Junita
10 months ago
Snort is great for intrusion detection, but it definitely doesn't cover all the orchestration and logging aspects mentioned in the question.
upvoted 0 times
...
Yuette
10 months ago
I feel like NextGen IPS could be relevant, but it seems more focused on prevention rather than incident response automation.
upvoted 0 times
...
Kati
10 months ago
I remember studying SIEM solutions for logging and compiling data, but they don't really handle orchestration like case management, right?
upvoted 0 times
...
Beatriz
10 months ago
I think the answer might be SOAR since it focuses on automating incident response workflows, but I'm not entirely sure.
upvoted 0 times
...
Anisha
10 months ago
I'm a little confused by the options. NextGen IPS and Snort seem more focused on intrusion prevention, which isn't the main requirement here. I think I'll rule those out and focus on comparing SIEM vs SOAR to determine the best fit.
upvoted 0 times
...
Filiberto
11 months ago
Okay, let's see. SIEM handles log aggregation and analysis, but doesn't necessarily provide the orchestration and automation features mentioned. SOAR seems like the more comprehensive solution that meets all the needs described in the question. I'm leaning towards that as the best answer.
upvoted 0 times
...
Elinore
11 months ago
Hmm, I'm a bit unsure about this one. The requirements seem to overlap with both SIEM and SOAR capabilities. I'll need to think through the differences between those two solutions more carefully before deciding.
upvoted 0 times
...
Levi
11 months ago
This looks like a pretty straightforward question. I'd say the answer is SOAR, since it covers all the key requirements like compiling network data, logging from multiple sources, providing case management, and automating incident response.
upvoted 0 times
...
Noah
11 months ago
I think the answer is A) SIEM because it can compile network data and log information from many sources.
upvoted 0 times
...
Vonda
11 months ago
Snort? Really? That's an intrusion detection system, not a comprehensive solution for all these requirements. Clearly SIEM or SOAR is the way to go.
upvoted 0 times
...
Felix
11 months ago
Hmm, I'm not sure SIEM or SOAR is the right answer. NextGen IPS might be more suitable for the network data compilation and incident response aspects.
upvoted 0 times
...
William
12 months ago
I'd go with SOAR. It's designed specifically for orchestration and automation, which is key for the case management and incident response workflows needed here.
upvoted 0 times
Audra
8 months ago
SIEM could work, but SOAR is more focused on orchestration.
upvoted 0 times
...
Gearldine
9 months ago
Agreed! Automation is crucial for incident response.
upvoted 0 times
...
Graciela
9 months ago
I think SOAR is the best choice too. It really streamlines processes.
upvoted 0 times
...
Dominga
9 months ago
Definitely SOAR! It handles everything we need efficiently.
upvoted 0 times
...
...
Rima
1 year ago
SIEM seems like the best fit for the requirements listed. It can handle all the tasks mentioned, like compiling network data, logging from multiple sources, and automating incident response workflows.
upvoted 0 times
Jose
12 months ago
I agree, SIEM is definitely the way to go for those tasks.
upvoted 0 times
...
...

Save Cancel