Your SOC uses a machine-learning model to flag anomalous logon behavior. After a cloud migration and a new remote-work policy, the model still runs but misses several unusual access patterns. Which action best addresses this outcome?
Select an answer to reveal the explanation.
Short Explanation
Think of the model like a security camera trained on yesterday's hallways. If your office layout changes, the camera still works but stops seeing the right things, so you'd need to watch its accuracy and retrain it. Tuning thresholds or swapping in rules just papers over drift.
Full Explanation
Model drift is the gradual loss of predictive value when the inputs or attacker behavior that a model learned no longer match production conditions. In this scenario, cloud migration and remote-work changes alter authentication patterns, so the model's baseline becomes stale and detections degrade. The analyst should track metrics such as precision, recall, alert volume, and false-negative examples, then retrain or recalibrate when drift crosses an acceptable threshold. Rebuilding the pipeline from scratch is disproportionate because the model itself can be retrained; a full replacement adds risk and delays coverage without addressing the root cause. Lowering thresholds increases alert volume and may surface missed events, but it also raises false positives and can mask the underlying accuracy problem rather than measuring it. Replacing the model with signature rules ignores the legitimate value of adaptive anomaly detection and creates brittle coverage when behavior changes again. Exam caveat: CompTIA expects recognition of continuous AI monitoring and retraining as a lifecycle control, not one-time deployment. Operational check: compare current model detections against recent confirmed incidents and schedule retraining if recall or precision declines over the review period.