A SOC analyst reviews a case where a ransomware alert was triaged after several hours because the queue contained hundreds of low-severity alerts. The analyst is asked to explain why high alert volume can reduce detection quality. Which condition best describes this risk?
Select an answer to reveal the explanation.
Short Explanation
Think of alert queues like a noisy radio: too many static hits, and you start skipping real warnings. Your team isn't being careless; the volume is training them to tune out. The trap is blaming the alert rule alone—fatigue is the process problem that hides the true positive.
Full Explanation
High alert volume is a process-quality problem because triage is a human attention budget. When low-value or poorly tuned alerts dominate the queue, analysts expend cognitive effort on repetitive noise, which increases false-negative risk for genuine detections and delays meaningful acknowledgment. This is alert fatigue: the signal-to-noise imbalance that makes an analyst deprioritize a true positive, not a failure of the detection source itself. A short EDR retention window is a visibility gap, because events are unavailable for review rather than being ignored while present. A training gap can affect classification, but the scenario centers on queue pressure and delayed triage, not misunderstanding tactics or techniques. A SOAR action that closes alerts is a workflow or automation defect, not the core risk created by excessive low-value alerts. Exam caveat: choose the answer that names the operational consequence of volume, not a tool misconfiguration. Operational check: immediately review the top twenty alert types by count and false-positive rate, then tune, suppress, or automate low-value detections while preserving high-severity routing.