Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 11 Question 120 Discussion

An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectlytyped credentials. How should the workflow be improved to resolve these issues?
B) Change the SOAR configuration flow to remove the automatic remediation that is increasing the false positives and triggering threats
A) Meet with privileged users to increase awareness and modify the rules for threat tags and anomalous behavior alerts
D) Increase incorrect login tries and tune anomalous user behavior not to affect privileged accounts
C) Add a confirmation step through which SOAR informs the affected user and asks them to confirm whether they made the attempts

Cisco 350-201 Exam - Topic 11 Question 120 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 120
Topic #: 11
[All 350-201 Questions]

An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly

typed credentials. How should the workflow be improved to resolve these issues?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
An
2 months ago
Yes! It could reduce unnecessary alerts and improve accuracy.
upvoted 0 times
...
Pansy
2 months ago
Maybe add a learning phase for user behavior?
upvoted 0 times
...
Ashlyn
2 months ago
Agreed! Too many false positives are frustrating.
upvoted 0 times
...
Sonia
2 months ago
We need to fine-tune the detection parameters.
upvoted 0 times
...
Mila
4 months ago
Are they even using machine learning? Seems like a missed opportunity!
upvoted 0 times
...
Louann
4 months ago
I think they should add more context to the alerts.
upvoted 0 times
...
Valda
4 months ago
Wait, they blocked real users? That's a huge oversight!
upvoted 0 times
...
Valentin
4 months ago
Totally agree, false positives are a nightmare!
upvoted 0 times
...
Tyra
5 months ago
Sounds like they need better tuning on the detection algorithms.
upvoted 0 times
...
Aliza
5 months ago
This is why we can't have nice things. Gotta strike a balance between security and usability, folks.
upvoted 0 times
...
Chau
5 months ago
Definitely need to review the alert thresholds and incorporate user feedback to optimize the workflow. Can't have users getting locked out for no good reason.
upvoted 0 times
...
Jeffrey
5 months ago
Haha, looks like the security team needs to work on their "detect and respond" skills. Maybe they should try turning it off and on again?
upvoted 0 times
...
Gaston
5 months ago
Implementing a more robust anomaly detection model and whitelisting trusted user behavior patterns could help address these issues.
upvoted 0 times
...
Macy
5 months ago
The workflow needs to be fine-tuned to reduce false positives and avoid disrupting legitimate user activities.
upvoted 0 times
...
Tony
6 months ago
I feel like we should also look into whitelisting certain login times for users to avoid blocking legitimate access.
upvoted 0 times
...
Jade
6 months ago
This reminds me of a practice question about user behavior analytics. Maybe we should consider adding more context to the alerts?
upvoted 0 times
...
Queen
7 months ago
I’m not entirely sure, but I think implementing a feedback loop for users could help refine the detection process.
upvoted 0 times
...
Providencia
7 months ago
I remember we discussed tuning the thresholds for alerts to reduce false positives. Maybe adjusting the sensitivity could help?
upvoted 0 times
...
Buddy
7 months ago
This seems like a classic case of needing to balance security and usability. I'd suggest incorporating more user behavior baselines and anomaly scoring to reduce the overly aggressive blocking. Gotta keep the admins and VIPs happy!
upvoted 0 times
...
Son
7 months ago
I'm a little lost on where to start with this one. Maybe I should review some example SOAR workflows first to get a better sense of how to structure the improvements. Definitely don't want to make things worse for the users.
upvoted 0 times
...
Jill
7 months ago
Okay, let's think this through step-by-step. First, I'd analyze the alert data to identify common patterns in the false positives. Then I'd look at ways to adjust the rules or add more exceptions to catch those cases.
upvoted 0 times
...
Sharee
7 months ago
Ugh, this is frustrating. Clearly the workflow needs to be more nuanced to avoid disrupting legitimate user activity. I'd focus on fine-tuning the anomaly detection thresholds and incorporating more contextual factors.
upvoted 0 times
...
Stephaine
8 months ago
Hmm, this seems like a tricky one. I'd start by reviewing the workflow logic and looking for any overly broad or inflexible rules that might be triggering false positives.
upvoted 0 times
Ollie
1 month ago
What about implementing a learning mechanism to adapt over time?
upvoted 0 times
...
Tamra
1 month ago
Maybe adding more context to the alerts could help.
upvoted 0 times
...
Francisca
2 months ago
I agree, reviewing the rules is essential.
upvoted 0 times
...
...

Save Cancel