During a post-incident review, your SOC finds that an alert was triaged correctly but analysts manually correlated three log sources because the SIEM correlation rule was too broad. Which action best demonstrates continuous improvement for security operations efficiency?
Select an answer to reveal the explanation.
Short Explanation
Think of a post-incident review as your workshop: if the wrench was missing, don't just fix the car—label the drawer and teach the next mechanic. You update the detection, playbook, and training so the same friction doesn't drain the next analyst. If you only tune the rule, you still leave the human process broken.
Full Explanation
Post-incident reviews are the feedback loop that turns operational friction into durable process improvement. When analysts discover that a triage required extra manual correlation, the corrective action should flow into the artifacts that govern future work: the detection logic, the response playbook, and the training that teaches analysts how to use them. That combination reduces repeated toil, keeps institutional knowledge current, and makes efficiency gains auditable. Escalating the task to a senior analyst treats a systemic gap as a staffing exception, so the same manual burden remains for everyone else. Adding a log source without revising the correlation rule may increase telemetry volume while leaving the original noisy logic intact, which can worsen alert fatigue rather than improve triage speed. Creating a replacement detection and retiring the old one can address a technical symptom, but without updating the playbook and training, analysts may still follow outdated steps or lose context about why the change occurred. Exam caveat: CompTIA rewards answers that connect lessons learned to multiple operational controls, not just rule tuning. Operational check: after a review, verify the finding is linked to a revised rule ID, an updated playbook version, and completed analyst training.