SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard

A large enterprise is implementing a new endpoint detection and response (EDR) solution across its global network. After initial deployment, security analysts notice a significant increase in the number of alerts generated, many of which are benign activities. This is causing alert fatigue and delaying response to actual threats. Which of the following actions should the security team prioritize to address this issue?

  1. AIncrease the number of security analysts to handle the alert volume.
  2. BIntegrate the EDR with a Security Information and Event Management (SIEM) system only.
  3. CRefine EDR rules and baselines to filter out benign activities and tune thresholds.
  4. DDisable the EDR solution temporarily until false positives are reduced.
Show answer & explanation

Correct answer: C. Refine EDR rules and baselines to filter out benign activities and tune thresholds.

Refining EDR rules and baselines, along with tuning thresholds, is the most effective way to reduce the volume of false positives. This process helps the EDR solution better differentiate between legitimate and malicious activities, thereby reducing alert fatigue and allowing analysts to focus on real threats.

Why the other options are wrong

  • A. Increasing staff is a costly and often temporary solution that doesn't address the root cause of excessive false positives.
  • B. While SIEM integration is beneficial, it primarily centralizes alerts; it doesn't inherently reduce false positives generated by the EDR itself without proper tuning beforehand.
  • D. Disabling the EDR would leave the network unprotected, which is unacceptable.

EDR False Positive Reduction

The process of tuning Endpoint Detection and Response (EDR) rules, baselines, and thresholds to minimize the generation of benign alerts, thereby improving the signal-to-noise ratio and reducing alert fatigue for security analysts.

  • Crucial for operational efficiency.
  • Involves continuous tuning and learning.
  • Reduces alert fatigue.
  • Improves focus on actual threats.

Memory trick: Tune the noise, so the real alarms are heard.

More Security Operations and Administration questions