Your SOC receives an EDR alert showing a compromised user account using credentials from an unfamiliar country. A tested SOAR playbook can disable the AD account and open an incident ticket. You need rapid containment plus an integrated audit trail. Which action best meets both goals?
Select an answer to reveal the explanation.
Short Explanation
Think of a SOAR playbook like an assembly line for containment: it disables the account and files the ticket in one motion. You get speed, consistency, and a built-in audit trail instead of scattered manual edits. The trap is choosing something that only looks safe but leaves no clean, automated record.
Full Explanation
SOAR orchestration is used when a containment action is repeatable and needs both technical enforcement and a durable incident record. A playbook can call directory services to disable the account, then invoke the ticketing system to attach indicators, timestamps, actor context, and analyst notes. This creates an auditable chain of custody while reducing analyst fatigue and variation. It should also record who approved the run and why the containment was required. Manual disabling with an email summary may stop the immediate access, but it depends on individual steps and creates fragmented evidence rather than an orchestrated workflow. A SIEM suppression rule changes alert visibility, not account state, so the compromised credential remains active. A phishing simulation tests user behavior but does not revoke access or document containment. Exam caveat: CS0-004 expects you to choose automation that preserves governance and evidence, not merely the fastest technical action. Operational check: verify the playbook writes an immutable log entry for the directory change and links the ticket to the original alert ID.