16. Which of the following is most likely to be used as a just-in-time reference document within a security operations center?

Answer: C

Explanation:

Playbook is most likely to be used as a just-in-time reference document within a security operations center.

A playbook serves as a detailed guide that outlines procedures and responses for various security incidents, making it a crucial resource for quick reference during real-time operations.

A) Change management policy

A change management policy is primarily focused on how changes to systems and processes are managed within an organization. While important for overall governance, it does not provide immediate operational guidance for responding to security incidents, thus making it less suitable as a just-in-time reference document in a security operations center.

B) Risk profile

A risk profile assesses and categorizes potential risks to an organization, providing insights into vulnerabilities and threats. However, it does not serve as a practical guide for immediate action during security incidents, rendering it ineffective as a just-in-time reference document within a security operations center.

C) Playbook

A playbook is specifically designed to provide step-by-step procedures for handling various security scenarios. Its structured format allows security personnel to quickly access the necessary actions to take in response to incidents, making it the most appropriate choice for just-in-time reference in a security operations center.

D) SIEM profile

A SIEM (Security Information and Event Management) profile involves the configuration and operation of security event monitoring systems. While it is essential for ongoing monitoring and analysis, it does not provide the immediate, actionable procedures that a playbook does, making it less effective as a just-in-time reference document.

Conclusion

The playbook stands out as the most appropriate just-in-time reference document because it provides direct, actionable guidance for security incidents. Other options like the change management policy, risk profile, and SIEM profile do not offer the immediate, situation-specific instructions necessary for rapid response in a security operations center.