An AI-powered EDR alert flags a script as malicious, but the analyst needs to justify the decision to the incident commander. The SOC wants models that support investigation and reporting. Which AI capability should the analyst prioritize when evaluating the alerting model?
Select an answer to reveal the explanation.
Short Explanation
Think of an explainable AI alert like a detective showing you the fingerprints, not just shouting 'guilty'. If the model can point to the file path, command line, or parent process that drove the score, you can actually investigate it. That's why you want feature importance, not just a high accuracy badge.
Full Explanation
Explainability and interpretability describe an AI model's ability to reveal the factors behind a specific prediction. In security operations, this matters because an alert is only useful if an analyst can validate it, trace suspicious behavior, and document the rationale for escalation or closure. A model that returns feature importance—such as command-line arguments, parent process, file path, or network destination that increased the risk score—lets the analyst correlate the AI decision with EDR telemetry and incident-response evidence. High accuracy on historical data is valuable for overall model performance, but it does not tell you why a particular event was scored malicious, so it cannot substitute for investigative context. A low false-positive rate reduces alert volume and analyst fatigue, yet it remains a statistical outcome rather than an explanation of the flagged activity. Automated containment can limit impact quickly, but it should follow or accompany analyst understanding, not replace the reasoning needed to confirm a true positive or support reporting. Exam caveat: focus on why AI outputs must be interpretable for SOC workflows, not on tuning a specific vendor model. Operational check: before escalating an AI-generated alert, review the feature contributions or model rationale and map each highlighted factor to corresponding endpoint or network telemetry.