A security operations center (SOC) is implementing a SOAR platform to automate responses to phishing incidents. The playbook will include steps to automatically quarantine suspicious emails, delete them from user mailboxes, and block the sender's domain. Which element should the SOAR playbook incorporate to ensure the automated response does not cause unintended disruption?
Trap 1: An automatic rollback script that restores quarantined emails after…
Automatic rollback could reintroduce malicious content and does not address the need for oversight.
Trap 2: Integration with threat intelligence to verify the sender domain…
While threat intel helps, it may not prevent all false positives; the question asks about avoiding unintended disruption.
Trap 3: A manual approval step before executing any automated response
Full manual approval defeats the purpose of automation; a better approach is conditional approval only for high-risk actions.
- A
An automatic rollback script that restores quarantined emails after 24 hours if no user complaint
Why it fails: Automatic rollback could reintroduce malicious content and does not address the need for oversight.
- B
Integration with threat intelligence to verify the sender domain reputation score before blocking
Why it fails: While threat intel helps, it may not prevent all false positives; the question asks about avoiding unintended disruption.
- C
A confirmation step that prompts the analyst to approve the quarantine and deletion actions
Inserting a manual approval gate before quarantine and deletion lets an analyst validate each automated action, preventing the playbook from disrupting legitimate business email. This directly satisfies the stem's constraint that automated response must not cause unintended disruption.
- D
A manual approval step before executing any automated response
Why it fails: Full manual approval defeats the purpose of automation; a better approach is conditional approval only for high-risk actions.