QuestionQ94

Managing a Security Operations Center

Which SIEM alerting behavior below suggests probable false-positive activity?

  • A An alert that has not been triggered for a year sending 2,000 alerts over a 24-hour period
  • B An alert with a threshold that has never been triggered on the SIEM
  • C An alert triggering over 1,500 times per weeks since it was first added to the SIEM
  • D An alert triggered when an account logs in from more than one IP address at a time
Explanation

An alert that fires at a very high rate continuously from the time it is introduced is likely generating persistent noise rather than identifying meaningful security events. This pattern commonly indicates an overly sensitive or poorly tuned detection rule.

Community Discussion

No comments yet. Be the first to start the discussion!