Automation and orchestration

Core concepts

Automation runs a single task without manual intervention (scripting repetitive work) for consistency and fewer errors. Orchestration coordinates multiple automated tasks into a workflow (sequencing IR steps).

SOAR (Security Orchestration, Automation, and Response) tools run runbooks and enrich data, often paired with a SIEM.

A playbook is a checklist of actions for a specific incident (phishing response, say). A runbook is the automated version of a playbook, with defined human decision points.

When to automate

Automate repeatable, stable processes. The decision factors: complexity (routine backups get automated; complex IR gets orchestrated), cost (a cost-benefit including dev, implementation, maintenance), single points of failure (add redundancy and a manual fallback), technical debt (from suboptimal solutions, needing regular review), and ongoing supportability (skills, training, and API and webhook connections).

The benefits: efficiency, baseline enforcement, secure scaling, employee retention (less drudgery), faster reaction, and acting as a workforce multiplier.

Common automation targets

CI/CD

The exam’s CI/CD benefits list: code quality, faster releases, lower deployment risk, rollback.

Integrations and APIs

An API is a set of rules for accessing another application’s features programmatically. The common styles: REST (standard HTTP methods, JSON, lightweight) and SOAP (structured XML, more heavyweight and secure, for enterprise transactions).

Most automation depends on APIs and webhooks. Test APIs with curl (it transfers data over HTTP/HTTPS and returns a JSON response), useful in development and penetration testing.