A quarterly detection engineering report shows rule coverage for 80% of MITRE ATT&CK techniques, a 22% false-positive alert rate, and three recent intrusions with no matching rule. Which action based on the report most improves detection effectiveness over time?
Select an answer to reveal the explanation.
Short Explanation
Think of a detection report like a car dashboard: it tells you what’s noisy and what’s missing. You use those clues to tune the rules and close the gaps, not just to show a pretty coverage number.
Full Explanation
A detection engineering report is useful only when it drives the next engineering change. In this scenario, the report identifies both noisy rules and uncovered techniques, so the analyst should use the findings to tune rules and fill detection gaps. Tuning reduces false positives, while adding rules for missed techniques expands meaningful coverage. Increasing alert volume by lowering thresholds would worsen the false-positive rate and erode analyst trust in alerts. Publishing the coverage percentage as the primary success metric is misleading because coverage without quality measures can hide noise and missed detections. Closing all missed-detection tickets as false negatives without review ignores the root cause and prevents the organization from improving its detection posture. Exam caveat: CompTIA expects reporting to support continuous improvement, not vanity metrics or unchecked alert volume. Operational check: Review the report with detection engineers and create tickets to tune noisy rules and add detection logic for techniques observed in recent incidents.