Courseiva
hardMultiple Choice

Designing a SOAR Playbook for Phishing Incidents

A large enterprise is implementing a SOAR platform to automate incident response. The security team wants to create a playbook for handling phishing emails reported by users. The playbook should: 1) validate the reported email by checking headers and attachments, 2) automatically block the sender's domain at the email gateway if malicious, 3) create a ticket, and 4) send an automated response to the user. Which of the following describes the best approach to design this playbook?

Quick Answer

The answer is to use an automated triage step that extracts indicators, then present the verdict to an analyst in a manual approval step before executing blocks. This approach is correct because it balances automation efficiency with human oversight, ensuring that the SOAR playbook automation with approval validates the phishing email through header and attachment analysis before any irreversible action, like blocking the sender’s domain, is taken. On the CompTIA SecurityX CAS-004 exam, this tests your understanding of risk-based playbook design, where false positives are a major concern in automated incident response; a common trap is choosing a fully automated block without validation, which can disrupt business operations. Remember the memory tip: “Triage first, approve the block” — this reinforces that automated extraction and analysis should always precede a manual approval gate to prevent costly mistakes.

⚠ Common exam trap

CAS-005 often tests the balance between automation and human oversight, and candidates may choose fully automated blocking without considering the risk of false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an automated triage step that extracts indicators, then present the verdict to an analyst in a manual approval step before executing blocks.

The best approach is to use automated triage to extract indicators and then present the verdict to an analyst for manual approval before executing blocks. This balances automation with human oversight, reducing false positives and ensuring that blocking actions are justified. It also aligns with SOAR best practices of automating repetitive tasks while keeping critical decisions under human control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a ticket and route it to a junior analyst for manual investigation, then close after user acknowledgement.

    Why it's wrong here

    Routing to manual investigation defeats the automation the SOAR platform is being deployed to provide, and no header or attachment validation occurs. Human triage is correct where judgement or escalation is genuinely needed, not for a playbook whose steps are all machine-executable.

  • ✗

    Immediately sandbox the attachment and block the sender's domain if the sandbox reports malicious behavior.

    Why it's wrong here

    Sandboxing alone skips header validation and the ticket and user-response steps the playbook requires, and blocking follows only sandbox verdicts. Sandbox detonation is the right action when attachment analysis is the sole decision point, not when a multi-step workflow is specified.

  • ✓

    Use an automated triage step that extracts indicators, then present the verdict to an analyst in a manual approval step before executing blocks.

    Why this is correct

    Automated triage extracts headers, URLs and attachment hashes, but a human approval gate precedes the gateway block. This preserves containment speed while preventing a false positive from blocking a legitimate sender's entire domain, satisfying the requirement to validate before executing the block.

  • ✗

    Automatically delete the email from all users' inboxes and send a warning to the organization.

    Why it's wrong here

    Deleting the email organisation-wide bypasses header and attachment validation, may destroy evidence, and omits the ticket and user-response steps. Bulk remediation is appropriate after a confirmed campaign is identified, not as the initial action on a single user report.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CAS-005

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SOC team uses a SOAR platform to automate incident response. They want to ensure that playbooks run with minimal human intervention but still require approval for actions that could cause service disruption. Which approach should be used?

hard
  • A.Require analyst sign-off for every playbook action.
  • B.Use network isolation as a safety net for any action.
  • ✓ C.Implement conditional manual approval for destructive actions.
  • D.Configure the SOAR to automatically execute all playbook steps.

Why C: Implementing conditional manual approval for destructive actions allows playbooks to run automatically for most steps, but pauses for human approval when an action could cause service disruption. This balances automation with safety.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.