Quiz 13 Question 5 of 20

Your SOC receives an EDR alert showing a compromised user account using credentials from an unfamiliar country. A tested SOAR playbook can disable the AD account and open an incident ticket. You need rapid containment plus an integrated audit trail. Which action best meets both goals?

Select an answer to reveal the explanation.

Motivation