Security Operations
This domain carries 28% of the SY0-701 exam. Practise it with original questions that explain every answer option.
- Certification
- SY0-701
- Exam weight
- 28%
- Subdomains
- 9
- Objectives
- 47
What this domain covers
Example question from this domain
An AdTech company’s SOAR platform triggered alerts for anomalous, low-and-slow exfiltration of PII such as device IDs and IP addresses. Initial playbooks contained some indicators, but the full scope and persistence are still unclear. Which approach best uses SOAR to investigate the threat and improve future PII protection, especially to uncover unknown TTPs?
- Integrate new external threat intelligence feeds into SOAR to automatically block all connections matching newly published IoCs.
- Use SOAR to orchestrate threat-hunting queries across bid stream logs, CDN access logs, and consent management audit trails, then automate newly discovered internal IoCs into response playbooks.
- Manually isolate suspected servers and use standalone forensic tools, bypassing SOAR to prevent further leakage.
- Use SOAR only to generate GDPR and CCPA compliance reports, prioritizing legal obligations over active investigation.
Integrate new external threat intelligence feeds into SOAR to automatically block all connections matching newly published IoCs. — External threat feeds are useful, but a sophisticated low-and-slow attack may use environment-specific methods not yet in those feeds. Blocking known IoCs is reactive and can miss the root cause, persistence, and unknown TTPs needed to fully address the breach.
Use SOAR to orchestrate threat-hunting queries across bid stream logs, CDN access logs, and consent management audit trails, then automate newly discovered internal IoCs into response playbooks. — SOAR can coordinate searches across multiple high-volume data sources so hunters can look for subtle, previously unknown TTPs tied to PII exfiltration. Newly found internal IoCs can then be added to playbooks, improving future detection and response in a continuous feedback loop.
Manually isolate suspected servers and use standalone forensic tools, bypassing SOAR to prevent further leakage. — Manual investigation is important, but skipping SOAR wastes its ability to aggregate data, automate collection, and coordinate response actions. In a high-throughput AdTech environment, that makes containment slower and reduces the chance of building reusable detections for future incidents.
Use SOAR only to generate GDPR and CCPA compliance reports, prioritizing legal obligations over active investigation. — Compliance reporting matters, but it should follow containment and investigation. Using SOAR only for reports ignores the immediate need to identify scope, stop exfiltration, and eradicate the attacker, which is essential before accurate regulatory reporting can be completed.
Continue with SY0-701
Domain names and weightings follow the vendor's published exam guide. ExamNova questions are written in-house and are not exam dumps.