An AI tool ranks EDR detections and recommends containment. Analysts trust the ranking but fear false positives. Which control should be enforced before automated response?
Select an answer to reveal the explanation.
Short Explanation
Think of AI as a sharp-eyed spotter, not the person holding the fire extinguisher. You can let it rank alerts, but don't pull the trigger unless a playbook says you may — and it has a rollback if it misfires. That keeps smart detection from turning into a self-inflicted outage.
Full Explanation
AI-assisted detection ranking is useful because it can triage large alert volumes and surface likely malicious events faster than manual review. However, automated response changes the risk model: a false positive can disrupt production, sever legitimate access, or hide evidence. A policy-approved playbook with rollback steps separates model confidence from operational authority by defining what can be automated, under what thresholds, who can approve exceptions, and how to reverse actions safely. Retraining the model on confirmed incidents can improve detection quality, but it does not create a safe boundary for autonomous action; feedback loops can also reinforce analyst bias if not governed. Auto-quarantining endpoints when confidence exceeds a fixed score is tempting, yet confidence is not proof of business impact and a high score can still reflect noisy telemetry or a misconfigured agent. Replacing SIEM correlation rules with AI-generated alerts removes deterministic logic and auditability, making detection harder to tune and validate. Exam caveat: CompTIA expects you to treat AI as decision support unless governance explicitly authorizes bounded automation. Operational check: Review the SOAR playbook and require a rollback action, approval path, and exception process for every AI-triggered containment step.