A SOC's ML-based anomaly detector alerts on a developer's first approved bulk export to a new cloud storage service. Traffic is encrypted, the destination is trusted, and a change ticket confirms the action. The analyst notes the behavior is legitimate but has no historical baseline for this user. Which AI concept best explains the alert?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a guard who memorized every normal door and then freaks out at a new badge. You need to recognize that legitimate change can look malicious until the model learns it. Don't tune the alert away; validate the business process and retrain with the new baseline.
Full Explanation
Machine-learning anomaly detection often learns a baseline of expected activity and flags deviations. When the learned baseline is too tightly matched to past behavior, the model treats a new but authorized pattern as suspicious, producing a false positive. In operations, the analyst confirms the activity through change control, identity context, and destination reputation, then records the outcome so the model can be retrained or a suppression policy can be applied. A misclassified signed binary would be an endpoint detection logic problem, not an AI generalization issue, and would not explain a network behavior absent process anomalies. An excessive SIEM threshold typically reduces alerts rather than creating an alert on a confirmed legitimate change, so it does not fit this scenario. Outdated threat-intel indicators can cause stale or incorrect matches, but they do not make a model overreact to a novel internal behavior. Exam caveat: CompTIA may ask you to distinguish false positives caused by limited training data from false negatives caused by weak detection logic. Operational check: review the alert against approved change records and add the validated benign pattern to the model's training data or exception workflow.