A SIEM rule is generating 500 alerts per day but only 2 are confirmed incidents. The SOC team is overwhelmed. What is this situation called and what is the best remediation?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because a high false positive rate leads to alert fatigue, and the proper remediation is rule tuning — adding context, whitelist conditions, or correlated conditions to reduce noise while maintaining detection of real threats. B is wrong because adding analysts treats the symptom without addressing the root cause of poor rule specificity.
Full explanation below image
Full Explanation
A is correct because a high false positive rate leads to alert fatigue, and the proper remediation is rule tuning — adding context, whitelist conditions, or correlated conditions to reduce noise while maintaining detection of real threats. B is wrong because adding analysts treats the symptom without addressing the root cause of poor rule specificity. C is wrong because the rule is generating many alerts, indicating ingestion is working; the problem is alert quality. D is wrong because this is a tuning problem, not a signature age problem.