Reader small image

You're reading from  CompTIA CASP+ CAS-004 Certification Guide

Product typeBook
Published inMar 2022
PublisherPackt
ISBN-139781801816779
Edition1st Edition
Right arrow
Author (1)
Mark Birch
Mark Birch
author image
Mark Birch

Mark Birch is an experienced courseware developer and teacher in both information systems and cyber-security. Mark has been developing content and teaching CompTIA A+ classes for more than 20 years and understands the subject area in great depth. Mark began his career working within the aerospace industry (for a major defense contractor) and has over 30 years' experience consulting, engineering, and deploying secure information systems. He has spent over 20 years working with the United States Military and United Kingdom Armed Forces, helping many students attain their learning goals. Mark has ensured that soldiers, officers, and civilians have had the best opportunities to gain cyber-security accreditation.
Read more about Mark Birch

Right arrow

Responses

When we have many security tools to guard our networks, it is important that we use automation to identify events and where possible to provide an automated response. This frees up the security operation center (SOC) staff to be able to take on board other useful security tasks. Security Orchestration Automation and Response (SOAR) is a modern approach to respond to real-time threats and alerts. Playbooks can be used to create or provide an automated response. A playbook could be a simple ruleset or a complex set of actions.

Firewall rules

Firewall rules are important to have in place, as they protect your perimeter network services placed in your Demilitarized Zone (DMZ). Firewall rules will also protect your internal resources when deployed as host-based firewalls. Firewall rules may be modified based upon a changing threat landscape and new adversaries. Bad actor IP address ranges may need to be updated on your firewalls.

Intrusion prevention system and intrusion...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
CompTIA CASP+ CAS-004 Certification Guide
Published in: Mar 2022Publisher: PacktISBN-13: 9781801816779

Author (1)

author image
Mark Birch

Mark Birch is an experienced courseware developer and teacher in both information systems and cyber-security. Mark has been developing content and teaching CompTIA A+ classes for more than 20 years and understands the subject area in great depth. Mark began his career working within the aerospace industry (for a major defense contractor) and has over 30 years' experience consulting, engineering, and deploying secure information systems. He has spent over 20 years working with the United States Military and United Kingdom Armed Forces, helping many students attain their learning goals. Mark has ensured that soldiers, officers, and civilians have had the best opportunities to gain cyber-security accreditation.
Read more about Mark Birch