Security Orchestration Automation and Response Flashcards
1
Q
What is SOAR?
A
Security Orchestration Automation and Response
Security tools to help incident response, threat hunting, and security configuration. Essentially, its SIEM 2.0 or Next-gen SIEM
2
Q
What is SOAR primarily used for?
A
Incident response, but it is used a lot in threat hunting as well.
3
Q
What is a Playbook?
A
A checklist of actions to perform to detect and respond to a type of incident. Can be manual or automated.
4
Q
What is a Runbook?
A
A automated version of a playbook that leaves clearly defined interaction points for human analysis.