You need a software solution that performs the following tasks:
Compiles network data
Logs information from many sources
Provides orchestration in the form of case management
Automates incident response workflows
What product should you use?
The CCST Cybersecurity Study Guide explains that SOAR (Security Orchestration, Automation, and Response) platforms integrate data from multiple tools and sources, support case management, and automate security workflows for faster incident response.
'SOAR solutions provide orchestration, automation, and response capabilities. They collect security data from multiple systems, enable analysts to manage incidents, and automate repetitive tasks in the response process.'
(CCST Cybersecurity, Incident Handling, Security Automation Tools section, Cisco Networking Academy)
A (SIEM) collects and correlates security logs but lacks full orchestration and automated response capabilities.
B is correct: SOAR adds orchestration, case management, and automated incident response.
C (NextGen IPS) focuses on intrusion prevention, not orchestration.
D (Snort) is an open-source intrusion detection/prevention tool, not an orchestration platform.
Rachael
8 months agoNoemi
8 months agoJolanda
8 months agoJuan
9 months agoAmber
9 months agoJunita
10 months agoYuette
10 months agoKati
10 months agoBeatriz
10 months agoAnisha
10 months agoFiliberto
11 months agoElinore
11 months agoLevi
11 months agoNoah
11 months agoVonda
11 months agoFelix
11 months agoWilliam
12 months agoAudra
8 months agoGearldine
9 months agoGraciela
9 months agoDominga
9 months agoRima
1 year agoJose
12 months ago