A SOAR playbook receives an EDR alert that a critical application server may be compromised. The playbook pauses and requests analyst approval before isolating the server from the network. Which action should the analyst take?
Select an answer to reveal the explanation.
Short Explanation
Think of a SOAR approval gate like a handbrake on a fast car: it’s there to stop automation from doing something drastic when the outcome is still fuzzy. You need to weigh the business impact and the containment scope before letting the playbook isolate a critical server. Approving it without that check turns speed into collateral damage.
Full Explanation
Human-in-the-loop containment is applied when an automated response could materially affect availability, safety, or business dependencies. In this pattern, the analyst confirms the alert's confidence, the asset's criticality, and the blast radius before approving network isolation. That review matters because a critical server may support authentication, payments, or clinical systems, and isolation may be the right control only after confirming that alternative containment is insufficient. Treating reversibility as sufficient is incorrect; a reversible action can still cause an outage or break a regulated process. Delaying containment until full forensic imaging is completed is also incorrect, because containment can stop spread while evidence preservation is performed through triage collection, memory capture, or post-containment imaging. Requiring a routine maintenance window before isolation is similarly wrong when the incident demands prompt containment; emergency change procedures may be used instead. Exam caveat: when a playbook explicitly pauses, the tested decision is whether human judgment is required for impact, not whether automation is slow. Operational check: before approving isolation, verify the asset owner, critical dependencies, and whether a narrower containment action can reduce business impact.