CompTIA Security+ (SY0-701)Security OperationsMedium
A SOC analyst notices that a SIEM dashboard is generating hundreds of low-fidelity alerts daily, causing analysts to miss genuine threats. Which action would MOST effectively address this issue?
- ATune correlation rules and thresholds to reduce false positives
- BRequire analysts to manually review every log entry individually
- CIncrease the number of raw log sources feeding into the SIEM
- DDisable all alerting rules until the backlog is cleared
Show answer & explanationAnswer & explanation
Correct answer: A. Tune correlation rules and thresholds to reduce false positives
Alert fatigue caused by excessive low-value alerts is best solved by tuning correlation rules, thresholds, and filters so the SIEM surfaces high-confidence, actionable alerts rather than noise.
Why the other options are wrong
- B. Manual review of every log entry is impractical at scale and doesn't fix root cause.
- C. Adding more raw log sources without tuning would worsen alert volume.
- D. Disabling alerting removes visibility into real threats entirely.
SIEM Rule Tuning
The process of adjusting correlation rules and alert thresholds in a SIEM to reduce false positives and alert fatigue while preserving detection of real threats.
- Alert fatigue leads to missed true positives
- Tuning reduces noise, improves signal-to-noise ratio
- Correlation rules combine multiple log events
- Ongoing tuning is a ongoing SOC maintenance task
Memory trick: Tune the noise, catch the signal.