mediumMultiple Choice
CAS-004 Practice Question: A SOC manager is considering implementing a SOAR…
A SOC manager is considering implementing a SOAR platform. Which is the primary benefit of SOAR in day-to-day operations?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated playbook execution and orchestration of response actions
SOAR automates repetitive tasks and orchestrates workflows, enabling faster and consistent incident response. Option B is wrong because SOAR is not primarily for centralized log storage; that's typically a SIEM or log management system. Option C is wrong because SOAR does not replace human analysts; it augments them. Option D is wrong because reducing false positive alerts is primarily a function of SIEM tuning, not SOAR. SOAR can help by automating responses, but it does not directly reduce false positives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated playbook execution and orchestration of response actions
Why this is correct
SOAR's primary operational benefit is executing automated playbooks that orchestrate response actions across tools, cutting mean time to respond. It satisfies the stem's day-to-day operations focus by replacing manual, repetitive triage and containment steps with machine-speed, consistent workflows.
- ✗
Centralized storage of all security logs
Why it's wrong here
Centralised log storage is a SIEM function; SOAR consumes alerts and executes playbooks rather than ingesting and retaining raw telemetry. It is tempting because SOAR platforms often display case data alongside logs, but the aggregation and retention role belongs to the SIEM or a data lake.
- ✗
Elimination of the need for human analysts
Why it's wrong here
SOAR orchestrates and automates repetitive triage tasks, but it still requires human analysts for judgement, escalation and novel threats, so it cannot eliminate them. It is tempting because automation reduces manual workload, and it would suit high-volume, repetitive alert handling where analysts remain in the loop.
- ✗
Reduction in false positive alerts from the SIEM
Why it's wrong here
SOAR orchestrates and automates response workflows; it does not tune SIEM correlation rules, which is what reduces false positives. It is tempting because automated enrichment and triage do help analysts dismiss noisy alerts faster, but the underlying detection logic remains the SIEM's responsibility.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.