Examlex

Solved

An Engineer Implemented a SOAR Workflow to Detect and Respond

question 57

Multiple Choice

An engineer implemented a SOAR workflow to detect and respond to incorrect login attempts and anomalous user behavior. Since the implementation, the security team has received dozens of false positive alerts and negative feedback from system administrators and privileged users. Several legitimate users were tagged as a threat and their accounts blocked, or credentials reset because of unexpected login times and incorrectly typed credentials. How should the workflow be improved to resolve these issues?


Definitions:

Crisis Type

classifies the nature or category of an emergency situation that affects individuals, organizations, or communities.

Serious Brand Crises

Situations that threaten a company's reputation and require immediate action to prevent damage.

Initial Fuss

The initial concerns or excitement about a new or controversial topic or issue.

Mainstream Media

Media outlets that reach a wide audience and are considered traditional or conventional sources of news and entertainment.

Related Questions