CompTIA Security+ (SY0-701)Security OperationsMedium

A SOC analyst notices that a SIEM dashboard is generating hundreds of low-fidelity alerts daily, causing analysts to miss genuine threats. Which action would MOST effectively address this issue?

  1. ATune correlation rules and thresholds to reduce false positives
  2. BRequire analysts to manually review every log entry individually
  3. CIncrease the number of raw log sources feeding into the SIEM
  4. DDisable all alerting rules until the backlog is cleared
Show answer & explanation

Correct answer: A. Tune correlation rules and thresholds to reduce false positives

Alert fatigue caused by excessive low-value alerts is best solved by tuning correlation rules, thresholds, and filters so the SIEM surfaces high-confidence, actionable alerts rather than noise.

Why the other options are wrong

  • B. Manual review of every log entry is impractical at scale and doesn't fix root cause.
  • C. Adding more raw log sources without tuning would worsen alert volume.
  • D. Disabling alerting removes visibility into real threats entirely.

SIEM Rule Tuning

The process of adjusting correlation rules and alert thresholds in a SIEM to reduce false positives and alert fatigue while preserving detection of real threats.

  • Alert fatigue leads to missed true positives
  • Tuning reduces noise, improves signal-to-noise ratio
  • Correlation rules combine multiple log events
  • Ongoing tuning is a ongoing SOC maintenance task

Memory trick: Tune the noise, catch the signal.

More Security Operations questions