A SOAR playbook uses an AI assistant to summarize a suspicious authentication alert. The summary states the user downloaded malware from a phishing site, but the SIEM only shows a failed login and no file transfer. What should the analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of AI as a fast-talking intern: it sounds confident, but it can make stuff up. You have to check its story against the raw logs before you act, because the telemetry is what actually happened.
Full Explanation
AI systems that summarize alerts can generate fluent narratives by predicting likely incident patterns, not by enforcing a one-to-one link to source evidence. When an AI output asserts malware download but telemetry lacks file transfer or download artifacts, the analyst must treat the assertion as a hypothesis and validate it against raw SIEM, EDR, or NetFlow records. This preserves the evidentiary chain and prevents a hallucinated conclusion from driving containment, escalation, or threat hunting. Relying on the AI summary alone bypasses evidence validation and can create false positives or missed true positives. Tuning the model to suppress future false positives may eventually reduce noisy outputs, but it does not resolve the current incident and can hide real activity if applied without validation. Creating a detection rule for the alleged behavior institutionalizes an unconfirmed pattern, risking noisy alerts and biased hunting. Escalating immediately based only on the summary transfers an unverified claim into formal incident handling and can waste responder capacity. Exam caveat: CompTIA expects analysts to understand AI as assistive telemetry interpretation, not as an authoritative source of fact. Operational check: Pull the alert ID, correlate it with raw log fields and host process events, and record whether each AI assertion is supported before taking incident action.