Security Orchestration Automation and Response Flashcards

1
Q

What is SOAR?

A

Security Orchestration Automation and Response

Security tools to help incident response, threat hunting, and security configuration. Essentially, its SIEM 2.0 or Next-gen SIEM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is SOAR primarily used for?

A

Incident response, but it is used a lot in threat hunting as well.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Playbook?

A

A checklist of actions to perform to detect and respond to a type of incident. Can be manual or automated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Runbook?

A

A automated version of a playbook that leaves clearly defined interaction points for human analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly