What is a benefit to an organization of using SOAR as part of the SIEM system?
- SOAR would benefit smaller organizations because it requires no cybersecurity analyst involvement once installed.
- SOAR was designed to address critical security events and high-end investigation.
- SOAR automates incident investigation and responds to workflows based on playbooks.
- SOAR automation guarantees an uptime factor of “5 nines”.
Answers Explanation & Hints:
SIEM systems are used for collecting and filtering data, detecting and classifying threats, and analyzing and investigating threats. SOAR technology does the same as SIEMs but it also includes automation. SOAR integrates threat intelligence and automates incident investigation. SOAR also responds to events using response workflows based on previously developed playbooks.