A SOC analyst reviews alerts generated by a new AI model trained on six months of noisy, incomplete network logs. Several high-severity detections correlate with benign backup traffic, and the team has no documented validation dataset. The analyst needs to decide how to treat the model’s output while improving it. Which action best reflects proper AI evaluation in security operations?
Select an answer to reveal the explanation.
Short Explanation
Think of an AI model like a new analyst trained on messy notes: if the notes are incomplete, the conclusions are shaky. You shouldn’t trust its alerts just because the machine said so; you need labeled validation data and tuning first. That’s how you avoid turning backup traffic into a false emergency.
Full Explanation
AI-assisted detection is only as reliable as the data used to train and validate it. In this scenario, noisy, incomplete logs and no labeled validation set mean the model may have learned benign backup traffic as suspicious, so the analyst must assess data quality, create representative ground truth, and tune thresholds before allowing alerts to drive response. Treating model output as authoritative ignores the possibility of systematic bias and can create alert fatigue or missed detections. Waiting for every alert to be manually confirmed defeats the purpose of scalable AI triage and still leaves the model unvalidated. Suppressing all AI alerts or replacing SIEM correlation rules without first evaluating the model’s data and validation evidence removes potentially useful signal and does not address the root cause of poor training data. Exam caveat: CompTIA expects AI to augment, not replace, analyst judgment, especially when training data quality is uncertain. Operational check: Compare a sample of AI alerts against confirmed true and false positives from labeled logs, then document precision, recall, and required retraining before promoting the model to production.