組織は、事前定義されたプレイブックに基づいて、自動化された意思決定ポイントとアクションを使用して、インシデント対応プロセスをワークフローに統合したいと考えています。組織は次のうちどれを実装する必要がありますか?
正解:B
Why is SOAR used? To synchronize tools, accelerate response times, reduce alert fatigue, and compensate for the skill shortage gap. To collaborate with other analysts during investigations. To analyze workload, organize an analyst's tasks, and allow teams to respond using their own processes.
EDR
The Endpoint Detection and Response Solutions (EDR) market is defined as solutions that record and store endpoint-system-level behaviors, use various data analytics techniques to detect suspicious system behavior, provide contextual information, block malicious activity, and provide remediation suggestions to restore ...