Section 26.248 Automation and Orchestration Flashcards

Objective 4.7 Explain the importance of automation and orchestration related to secure operations

1
Q

Automation

A

Execution of tasks without manual intervention

Make individual tasks easier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Orchestration

A

Coordinated execution of multiple automated tasks for a specific outcome or workflow

Make multiple tasks easier to achieve broader goal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Orchestration, Automation, and Response

SOAR

A

Class of security tools for incident response, threat hunting, and security configurations

■ Purpose: Orchestrate and automate runbooks, deliver data enrichment

■ Example: Integrating SIEM and SOAR for advanced security capabilities

its like a next generation SIEM mainly seen in incident response as you can automate alot

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Playbook

A

Checklist of actions for detecting and responding to a specific incident

■ Role: Guides incident response processes

■ Example: Steps for responding to a phishing campaign

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Runbook

A

Automated version of a playbook with defined interaction points for human analysis

■ Role: Executes automated tasks with human decision points

■ Example: Automated incident response with analyst decision points

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Benefits of Automation and Orchestration

A

■ Efficiency: Time-saving and consistent execution

■ Standardisation: Enforces baselines and standardised configurations

■ Scalability: Scales securely and efficiently

■ Employee Retention: Reduces repetitive tasks

■ Reaction Time: Faster responses to incidents

■ Workforce Multiplier: Maximises human resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly