An enterprise SOC triage queue feeds alerts from SIEM, EDR, and a vulnerability scanner. Each alert includes severity, affected asset business value, and detection confidence. During a high-volume shift, an analyst must decide which alert to investigate first. Which prioritization method best reflects risk-based triage?
Select an answer to reveal the explanation.
Short Explanation
Think of triage like a hospital waiting room: the bleeding patient on a critical server gets seen before a scraped knee on a test box. Don't just chase the loudest severity or the oldest ticket; combine severity, asset value, and confidence to decide what's actually risky. That's how you keep the queue from turning into noise.
Full Explanation
Risk-based alert triage treats each event as a combination of potential impact and confidence, not as an isolated technical label. A practical method scores severity, asset business value, exploitability or blast radius, and detection confidence, then ranks alerts by the resulting risk score. This lets analysts work consequential, reliable events first, reducing dwell time on real incidents and preventing low-value noise from consuming limited SOC capacity. In hybrid estates, identical alerts on a domain controller and a sandbox host can carry very different operational consequences.
Prioritizing solely by severity ignores asset value and confidence, so a medium-confidence alert on a test system may outrank a high-value production indicator. Chronological handling imposes a first-in-first-out queue that rewards backlog age rather than risk, allowing a serious recent event to wait behind an older low-impact alert. Clearing the tool with the most detections biases work toward noisy sources and can drown out lower-volume but higher-confidence telemetry from endpoint or identity systems. Each wrong approach optimizes a convenient metric instead of organizational risk.
Exam caveat: CS0-004 expects triage as risk-informed decision-making, not ticket aging, alert volume, or raw severity sorting. Operational check: Publish a triage scorecard that multiplies severity, asset criticality, and detection confidence, then review the top ten ranked alerts at shift handoff.