CAS-004 Security Operations Practice Question
A SOC team is implementing a SOAR playbook to automate the response to phishing emails reported by users. The playbook should perform initial triage and, if the email is determined to be malicious, take containment actions. Which TWO of the following actions should be included in the playbook? (Choose TWO.)
⚠ Common exam trap
The trap is selecting administrative or heavy remediation actions (ticket creation, manager approval, full AV scan) instead of the core triage and containment actions (IOC extraction and sender blocking); candidates must distinguish between 'nice to have' workflow steps and the essential automated triage/containment actions the question asks for.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automatically block the sender's email address in the email gateway
Option E is correct because extracting embedded URLs and file hashes is a core initial triage step in a phishing SOAR playbook — these indicators are submitted to threat intelligence platforms (e.g., VirusTotal, MISP) to determine whether the email is malicious before any containment action is taken. Option C is correct because, once the email is confirmed malicious, blocking the sender's address at the email gateway is a standard, low-risk containment action that prevents further messages from that sender reaching other users. Option A is not appropriate because requiring manager approval introduces a manual delay that defeats the purpose of an automated SOAR playbook and is not a triage or containment action. Option B is not a triage or containment action; ticketing is a documentation/notification step, not part of the initial decision or containment logic. Option D is not indicated here because a full antivirus scan on the workstation is a host-level remediation action that is not triggered by email triage alone and would typically follow only if the user executed an attachment or payload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send an alert to the user's manager for approval
Why it's wrong here
Manager approval inserts a human authorisation step, which halts automated containment and delays isolation of the malicious email; SOAR playbooks execute containment directly once triage confirms malice. It is tempting because approval gates suit high-impact destructive actions, but phishing containment needs immediate automated quarantine, not managerial sign-off.
- ✗
Automatically create a ticket in the service desk system
Why it's wrong here
Ticket creation records the incident but performs no triage or containment, so the malicious email remains in the mailbox and other recipients stay exposed. It is tempting because ticketing is standard SOC practice for audit trails, but that fits post-containment documentation, not the containment actions this playbook must execute.
- ✓
Automatically block the sender's email address in the email gateway
Why this is correct
Blocking the sender's address at the gateway contains the campaign, preventing further delivery from that source to any recipient. This satisfies the playbook's containment requirement once triage confirms the email is malicious, limiting spread without manual intervention.
- ✗
Initiate a full antivirus scan on the user's workstation
Why it's wrong here
Initiating a full antivirus scan on the user's workstation is a remediation step that occurs after containment, not a containment action itself. The playbook specifically requires immediate containment to stop the threat from spreading, such as disabling the user's account or isolating the host via network access control. This option is tempting because antivirus scans are a standard response to confirmed malware, and they would be correct in a playbook focused on post-containment eradication or endpoint cleanup, where the goal is to remove the malicious payload rather than halt lateral movement.
- ✓
Extract embedded URLs and file hashes for threat intelligence lookup
Why this is correct
Extracting embedded URLs and file hashes feeds them to threat intelligence platforms, enriching triage with reputation and campaign context. This satisfies the initial triage stage, letting the playbook decide automatically whether the reported email is malicious before containment actions run.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.