CFS136 · Principles of Information Security

Chapter 13 Review: Automation and Orchestration

A hands-on review station for security automation, SOAR playbooks, Infrastructure as Code, AI and machine learning in security operations, and the human-in-the-loop decisions from Chapter 13.

Start Here

Five review stations, each a different way to practice Chapter 13. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Distinguish among security automation (running actions without a human), orchestration (coordinating tools into a workflow), and integration (connecting tools so they can exchange data).
  • Explain how a SOAR platform uses playbooks to automate incident response, and how it differs from a SIEM.
  • Apply Infrastructure as Code security principles, including the large blast radius of a compromised pipeline and the controls that reduce it.
  • Assess AI and machine learning uses such as behavioral analytics, anomaly detection, and automated risk scoring, along with their limits.
  • Weigh the benefits and risks of automation and identify when a human-in-the-loop decision is required.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/20Terms viewed
0/10Concepts matched
0/10Benefits and risks correct
0/8Decisions correct
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.