nerdexam
EC-Council

312-39 · Question #17

A financial institution's SIEM is generating a high number of false positives, causing alert fatigue among SOC analysts. To reduce this burden and improve threat detection accuracy, the organization…

The correct answer is A. Dynamic rule optimization. Dynamic rule optimization best explains a reduction in false positives and redundant alerts after adding AI to a SIEM. In SOC operations, alert fatigue often comes from static thresholds, overly broad correlations, and detections that don’t adapt to changing baselines (new…

Security Incident Detection

Question

A financial institution's SIEM is generating a high number of false positives, causing alert fatigue among SOC analysts. To reduce this burden and improve threat detection accuracy, the organization integrates AI capabilities into the SIEM. After implementation, the SOC team observes a significant decrease in redundant alerts, along with faster detection of genuine threats. Which AI capability contributed to this improvement?

Options

  • ADynamic rule optimization
  • BRule validation and testing
  • CAutomated rule generation
  • DData integration enhancement

How the community answered

(28 responses)
  • A
    75% (21)
  • B
    14% (4)
  • C
    4% (1)
  • D
    7% (2)

Explanation

Dynamic rule optimization best explains a reduction in false positives and redundant alerts after adding AI to a SIEM. In SOC operations, alert fatigue often comes from static thresholds, overly broad correlations, and detections that don’t adapt to changing baselines (new business apps, seasonal activity, infrastructure changes). AI-driven dynamic optimization can tune thresholds, suppress noisy patterns, and adjust scoring based on context (user role, device posture, known maintenance windows, historical behavior). This reduces duplicate/low-value alerts while preserving or improving sensitivity for real threats, which aligns with “decrease in redundant alerts” and “faster detection of genuine threats.” Rule validation/testing improves quality but is usually a manual or pre-deployment activity, not a continuous adaptive capability. Automated rule generation might create new detections, but it doesn’t inherently reduce noise unless paired with tuning. Data integration enhancement improves coverage and correlation, but by itself it can increase alerts if not tuned. The described outcome-less noise, better precision, quicker true detection-matches adaptive tuning and optimization of detections over time, which is dynamic rule optimization.

Topics

#AI in SIEM#dynamic rule optimization#false positive reduction#alert fatigue

Community Discussion

No community discussion yet for this question.

Full 312-39 Practice