A SOC uses an automated playbook that enriches EDR alerts, creates tickets, and assigns severity. During a SIEM collector outage, alert ingestion stalls, playbook executions fail, and no tickets are generated for three hours. The analyst wants to ensure incidents are not silently missed when automation cannot complete. Which playbook design change is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Think of automation like a conveyor belt: if it stops, you need a bucket underneath so work doesn't hit the floor. A monitored fallback workflow keeps the alerts in a durable queue and hands them to a human when the playbook fails. That way, a broken integration becomes a visible queue, not a silent gap.
Full Explanation
Automated SOC workflows improve efficiency, but they also introduce a failure mode: if a SIEM, ticketing API, or enrichment service is unavailable, alerts may never become actionable items. The durable design is a monitored fallback workflow that detects execution errors, preserves enough alert context in a durable queue or dead-letter store, and escalates to manual triage with service-level targets. This converts automation failure into a visible backlog instead of a silent loss of telemetry. A report delivered after the fact may help process improvement, but it does not prevent missed incidents during the outage window. Automatic deletion of failed alerts removes evidence and can discard true positives simply because enrichment could not run. A single retry followed by closing the alert as non-actionable creates false assurance; it assumes transient failure without verifying whether the alert represented a real incident. Exam caveat: CS0-004 treats efficiency as process reliability, not just speed, so automation must include exception handling and human escalation. Operational check: review a failed playbook run and verify that the alert remains queryable, an alert-to-ticket gap is monitored, and a named queue is paged when integration errors exceed the threshold.