160k views
1 vote
Steps to verify intrusion detection system alerts and perform more repetitive steps to mitigate well-known attacks. Of the following choices, what can automate these steps?

1) Security Orchestration, Automation and Response (SOAR)
2) Security Information and Event Management (SIEM)
3) Network Intrusion Detection System (NIDS)
4) Data Loss Prevention System

1 Answer

1 vote

Final answer:

The tool used to automate the verification of intrusion detection system alerts and repetitive mitigation steps for well-known attacks is Security Orchestration, Automation, and Response (SOAR).

Step-by-step explanation:

To automate the steps of verifying intrusion detection system alerts and perform more repetitive steps to mitigate well-known attacks, the best tool is Security Orchestration, Automation, and Response (SOAR). While Security Information and Event Management (SIEM) systems are excellent for aggregating and analyzing data from various security feeds, they are not specifically designed for automation of response procedures. A Network Intrusion Detection System (NIDS) is responsible for detecting intrusions and alerting the appropriate parties, but it does not automate responses. A Data Loss Prevention System focuses on ensuring that sensitive data does not leave the network unauthorized, which is not directly related to automating responses to intrusions.

SOAR platforms are specifically designed to streamline security operations in a variety of ways, including the automation of common incident response tasks. They can take inputs from various sources, such as SIEMs and NIDS, and execute a predetermined set of actions to help mitigate and respond to threats in an efficient and timely manner.

User Dqw
by
6.5k points