アナリストは、社内でフィッシング攻撃を手動で処理する現在のプロセスは効果的ではないと判断しました。アナリストは、フィッシング攻撃が社内で適切かつタイムリーに処理されるようにするための新しいプロセスを開発しています。アナリストの要件の 1 つは、フィッシング攻撃が特定されたときにブロックリストを自動的に更新することです。次のどれがこの要件を満たすのに役立ちますか?
正解:A
To automate the process of handling phishing attempts and updating blocklists, the best solution is to implement SOAR (Security Orchestration, Automation, and Response). SOAR platforms allow organizations to define automated workflows for responding to security incidents, such as phishing attacks. In this case, SOAR can automate the identification of phishing attempts and update blocklists in real-time, improving response time and consistency. MSSP (Managed Security Service Provider) and MDR (Managed Detection and Response) are outsourced services that do not directly address the need for automation, and containerization and virtualization are unrelated to incident handling. CASP+ emphasizes the value of automation in streamlining security operations and improving response times to threats.
References:
* CASP+ CAS-004 Exam Objectives: Domain 2.0 - Enterprise Security Operations (Automation, SOAR)
* CompTIA CASP+ Study Guide: Security Automation and Incident Response with SOAR