NSE 2 Lesson 8 – NSE 2 SOAR

NSE 2 Lesson 8 – NSE 2 SOAR

Question text

Question 1

Which is a benefit of SOAR?

Select one:

  • It deflects DDoS attacks and identifies the Command and Control source
  • It reports on which endpoints require patching and have security vulnerabilities
  • It increases security team efficacy by automating repetitive processes
  • It analyzes and generates a security score to measure improvements in network security

Question 2

Question text

What are playbooks used for?

Select one:

  • To automate the actions that an analyst would typically do manually
  • To describe the order in which analysts complete tasks
  • To provide a set of scenarios of predicted cyberattack methods
  • To plan a set of manual tasks to be completed by analysts

Question 3

Question text

What is a common use case for an implementation of SOAR by customers?

Select one:

  • Detecting zero-day attacks  
  • Phishing investigations
  • Logging events and alerts
  • Guarding against DoS attacks

Question 4

Question text

What is alert fatigue?

Select one:

  • The SOAR system is overloaded by the amount of network traffic
  • Measures the time lag to resolve alerts
  • Analysts are overwhelmed by the number of alerts
  • Analysts reduce the number of alerts using SOAR

Question 5

Question text

What are three reasons SOAR is used? (Choose three.)

Select one or more:

  • Analyze workload
  • Collaborate with other analysts
  • Reduce alert fatigue
  • Accelerate response times
  • Compensate for the skill shortage

NSE Lesson 7