Which Should a SOC Use to Improve Incident Response Procedure?

Which of the following should a security operations center use to improve its incident response procedure?

  1. Playbooks Source Reference Answer
  2. Frameworks
  3. Baselines
  4. Benchmarks

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the distinction between playbooks (specific step-by-step procedures) and frameworks (general structures), with playbooks being the direct answer to improving procedures.

In the SY0-701 exam, playbooks are the correct answer for improving a SOC's incident response procedure because they provide step-by-step instructions. The community overwhelmingly supports playbooks, clarifying their role as specific procedural guides.

Choosing B. Frameworks is common because they provide incident response structure, but they are not as specific as playbooks, which directly outline steps for a given incident.

Community Discussion (3 comments)

jafyyy 👍 6
A. Playbooks Its a step by step procedure outlining how to respond to specific types of incidents.
StringerBarksdale 👍 2
The answer is B
qacollin 👍 3 Selected: A
A. GPT

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Playbooks are essential for an SOC because they provide detailed, step-by-step procedures for responding to specific incident types. This aligns with the community comment stating they are 'a step by step procedure outlining how to respond to specific types of incidents.' By using playbooks, analysts can act quickly and consistently, reducing errors and improving response time.

Why the Other Options Are Wrong

Frameworks (B) provide the overall architecture and high-level phases for incident response but lack the detailed, prescriptive steps needed for a single procedure. Baselines (C) and benchmarks (D) are security configuration references, not procedural response tools. Therefore, they do not directly improve the incident response procedure itself.

Community Comment Notes

Most comments support A, with one remark highlighting playbooks as step-by-step guides. A dissenting comment chose B, but this reflects a common misunderstanding of the difference between a framework and a playbook. The expert consensus and exam objectives clearly point to playbooks as the correct answer for improving procedures.

Official Reference

Exam Strategy

When answering incident response questions, look for keywords like 'procedure' or 'step-by-step'—these almost always point to playbooks. Remember that frameworks are broader and provide structure, while playbooks are the specific actionable recipes for incidents.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide