An AI-assisted SOAR workflow recommends disabling a production service account after anomalous sign-ins. The analyst must choose how to handle the recommendation. Which action best reflects responsible AI use in security operations?
Select an answer to reveal the explanation.
Short Explanation
Think of AI like a fast junior analyst: great at spotting patterns, but not always safe to let it pull the trigger. You need a human to approve actions that can take down production or lock out users. That's human-in-the-loop for consequential decisions.
Full Explanation
Responsible AI in security operations means matching automation authority to the potential impact of the action. AI can recommend account isolation, ticket enrichment, or policy changes, but when the action may disrupt production services or user access, a human analyst must validate context before execution. This preserves speed and consistency while preventing false positives from causing outage, lockout, or business harm. Allowing immediate automated execution favors response time over safety and ignores that AI output is probabilistic, not deterministic. Expanding autonomous authority over production systems increases the blast radius of model errors and conflicts with least privilege for automated actions. Removing approval steps to reduce workload may improve efficiency metrics but undermines accountability and can violate change-control expectations for consequential operations. Exam caveat: CompTIA often frames AI governance around transparency, bias, explainability, and human oversight, not simply automation speed. Operational check: define an approval matrix that requires analyst sign-off for any AI recommendation that disables accounts, changes firewall policy, or isolates endpoints.