Nightly authorized vulnerability scans of the library catalog keep creating the same notables. The search logic is correct. What should the analyst use so those known-benign items leave the working queue without deleting history?
Select an answer to reveal the explanation.
Short Explanation
The nightly library scan is a scheduled drill, not a break-in. Suppression tucks those notables out of the working pile without shredding the evidence. Rewrite the search only when the logic itself is wrong.
Full Explanation
Suppression on Incident Review / Analyst Queue hides known-benign notables that match a defined pattern while leaving the notable index intact. That is the right control when the analytic is correct and the activity is an authorized civic scan. Rewriting the search is appropriate when the logic is wrong, not when authorized noise should be temporarily hidden. Deleting notable history or labeling True Positive destroys audit value and misstates the outcome.