Your SOC receives many low-confidence EDR alerts and user emails asking whether messages are suspicious. Management wants to reduce analyst workload while preserving visibility. Which user-facing efficiency mechanism most directly addresses this?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a front desk: let people hand you the right form and say whether the visitor is expected. If users can report suspicious email and confirm benign activity, you stop analysts from chasing every noisy alert. The trap is thinking more automation always means bigger rules or bots; here the win is user-facing self-service that filters work before it reaches you.
Full Explanation
Self-service mechanisms improve security operations efficiency by moving low-confidence triage closer to the people who can supply context. A phishing-report button lets users submit suspicious messages to the SOC, while a benign-alert confirmation workflow lets them validate expected software, logon activity, or scheduled tasks. This reduces analyst queue time, preserves auditability, and feeds normalized data into SIEM or SOAR workflows. A manual validation requirement increases workload instead of reducing it, because every report still needs analyst review before closure. Raising SIEM correlation thresholds can reduce alert volume, but it does so by suppressing detections rather than empowering users and can hide true positives. A policy-only chatbot answers questions but does not collect or triage suspicious activity, so it does not address alert burden. Exam caveat: user confirmation must not let users close security incidents unilaterally; it should qualify alerts for analyst review. Operational check: enable a phishing-report button and benign-alert confirmation form, then measure whether analyst triage volume and mean time to acknowledge drop without losing confirmed incidents.