Security Operations
An analyst reviewing SIEM alerts wants to reduce noise by suppressing repeated benign events from a known vulnerability scanner. Which action best preserves detection capability while cutting alert volume?
- ADisable the correlation rule entirely across all hosts
- BCreate a tuning rule that excludes traffic from the scanner's known IP for that specific signatureCorrect
- CDelete all log sources associated with the scanner's subnet
- DLower the SIEM's overall logging retention to 7 days
Why: Tuning to exclude a known-good source for one signature removes false positives without blinding the SIEM to real threats. Deleting log sources or disabling the rule globally would create blind spots, and shortening retention harms investigations. Targeted allow-listing keeps fidelity high while reducing analyst fatigue.
Vulnerability Management
An analyst must prioritize remediation for a vulnerability with a CVSS base score of 9.8. Before escalating, which additional factor most improves prioritization accuracy?
- AEnvironmental and threat context such as asset exposure and active exploitationCorrect
- BThe vendor's marketing severity label only
- CThe alphabetical order of the affected hostname
- DThe number of characters in the CVE identifier
Why: A CVSS base score reflects intrinsic severity but ignores your environment; adding environmental metrics and threat intelligence (like known active exploitation) sharpens real-world risk. A 9.8 on an isolated, non-critical asset may rank below a 7.0 on an internet-facing crown-jewel system. Context-driven prioritization prevents wasting effort on theoretically severe but practically low-risk findings.