Skip to content

Automation and Standard Processes Questions

Practice questions for Automation and Standard Processes topic in Certified Implementation Specialist - Security Incident Response. 60 questions covering this domain.

60 questions16 easy32 medium12 hard
Q1
easy

How should security incident groups be configured for role inheritance to work as intended?

Q2
easy

An incident already has a specific playbook attached and it is still active. What happens if the analyst tries to add that same playbook again?

Q3
hard

Which statement correctly describes how inbound Security Operations email is handled after it reaches a configured email address?

Q4
medium

Which value is a valid Pending Item Visibility option in a playbook?

Q5
easy

A responder wants to start a playbook manually from an incident form. Which action should be used?

Q6
medium

What does the Get configuration items of affected users action provide to a playbook?

Q7
easy

What is the primary purpose of Setup Assistant in SIR?

Q8
medium

A second different playbook is added to a security incident that already has one active playbook. How do they run?

Q9
easy

How does user reported phishing create a security incident in SIR?

Q10
medium

Which statement correctly describes the Add observables to the security incident playbook action?

Q11
medium

A team built automation in Flow Designer and expects the playbook component to show it as a playbook in SIR. What is actually supported?

Q12
medium

What must be true for a playbook to invoke automatically on a security incident?

Q13
medium

A parent incident needs a consolidated list of unique affected users from all of its child incidents. Which playbook action is designed for that?

Q14
hard

An email transform uses a Record Separator to break one email into sections. When are records actually created from those sections?

Q15
hard

Which role can approve or reject time-off requests and manage gaps and conflicts in SIR On-Call Scheduling?

Q16
medium

Which action is available from within a playbook activity or card?

Q17
medium

Which outcome is a valid duplication rule for parsed Security Operations emails?

Q18
hard

For Security Operations plugins, what does the email_to property define?

Q19
medium

Which action retrieves all child incidents for a parent security incident and can support status or severity updates based on child count?

Q20
easy

Which action helps determine whether additional members of the same group may also be affected by an incident?

Sign in to see all 60 questions

Create a free account to browse all questions — completely free during our launch phase.