Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A SOC manager is considering implementing a SOAR…

A SOC manager is considering implementing a SOAR platform. Which is the primary benefit of SOAR in day-to-day operations?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated playbook execution and orchestration of response actions

SOAR automates repetitive tasks and orchestrates workflows, enabling faster and consistent incident response. Option B is wrong because SOAR is not primarily for centralized log storage; that's typically a SIEM or log management system. Option C is wrong because SOAR does not replace human analysts; it augments them. Option D is wrong because reducing false positive alerts is primarily a function of SIEM tuning, not SOAR. SOAR can help by automating responses, but it does not directly reduce false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automated playbook execution and orchestration of response actions

    Why this is correct

    SOAR's primary operational benefit is executing automated playbooks that orchestrate response actions across tools, cutting mean time to respond. It satisfies the stem's day-to-day operations focus by replacing manual, repetitive triage and containment steps with machine-speed, consistent workflows.

  • ✗

    Centralized storage of all security logs

    Why it's wrong here

    Centralised log storage is a SIEM function; SOAR consumes alerts and executes playbooks rather than ingesting and retaining raw telemetry. It is tempting because SOAR platforms often display case data alongside logs, but the aggregation and retention role belongs to the SIEM or a data lake.

  • ✗

    Elimination of the need for human analysts

    Why it's wrong here

    SOAR orchestrates and automates repetitive triage tasks, but it still requires human analysts for judgement, escalation and novel threats, so it cannot eliminate them. It is tempting because automation reduces manual workload, and it would suit high-volume, repetitive alert handling where analysts remain in the loop.

  • ✗

    Reduction in false positive alerts from the SIEM

    Why it's wrong here

    SOAR orchestrates and automates response workflows; it does not tune SIEM correlation rules, which is what reduces false positives. It is tempting because automated enrichment and triage do help analysts dismiss noisy alerts faster, but the underlying detection logic remains the SIEM's responsibility.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.