When automation can disable a user account or system, the engineer should coordinate and communicate that behavior to the IT Help Desk . Such containment actions directly affect users and business services and can immediately generate support calls, login failures, access-loss complaints, or outage reports.
The Help Desk therefore needs to understand what automated security actions may occur, how to recognize them, where to verify that security automation initiated the action, and how to escalate the case appropriately. Without this coordination, support personnel might unknowingly reverse a legitimate containment action—for example, re-enabling an account that SOAR disabled because of confirmed malicious activity.
Option C is a useful technical guardrail but does not answer the question ' s emphasis on an external support consideration . Playbook logging is important for auditability but does not establish coordination with another operational team. Adding a generic support tag does not provide the necessary organizational process.
The supplied course material supports this broader automation-safety principle through its OODA automation discussion, particularly the requirement to perform checks before consequential automated actions.
Study Guide topics: SOAR automation, containment, cross-functional coordination, Help Desk procedures, automation guardrails, operational support.