nerdexam
CompTIA

CS0-003 · Question #316

Which of the following techniques can help a SOC team to reduce the number of alerts related to the internal security activities that the analysts have to triage?

The correct answer is D. Add a SOAR rule to drop irrelevant and duplicated notifications. To effectively reduce alert fatigue for a SOC team, implementing a SOAR rule to automatically filter and drop irrelevant or duplicate notifications is the most effective approach.

Submitted by helene.fr· Mar 6, 2026Security operations

Question

Which of the following techniques can help a SOC team to reduce the number of alerts related to the internal security activities that the analysts have to triage?

Options

  • AEnrich the SIEM-ingested data to include all data required for triage
  • BSchedule a task to disable alerting when vulnerability scans are executing
  • CFilter all alarms in the SIEM with low seventy
  • DAdd a SOAR rule to drop irrelevant and duplicated notifications

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    3% (1)
  • D
    95% (35)

Why each option

To effectively reduce alert fatigue for a SOC team, implementing a SOAR rule to automatically filter and drop irrelevant or duplicate notifications is the most effective approach.

AEnrich the SIEM-ingested data to include all data required for triage

Enriching SIEM-ingested data makes alerts more informative and provides context, but it does not directly reduce the overall number of alerts received by analysts.

BSchedule a task to disable alerting when vulnerability scans are executing

Scheduling a task to disable alerting during vulnerability scans only addresses a specific type of internal activity and might miss other legitimate internal security events that could generate similar 'noise' or even hide malicious activity during those windows.

CFilter all alarms in the SIEM with low seventy

Filtering all alarms with low severity might suppress legitimate low-severity alerts that could be precursors to larger incidents, potentially leading to missed threats rather than just reducing irrelevant noise.

DAdd a SOAR rule to drop irrelevant and duplicated notificationsCorrect

A Security Orchestration, Automation, and Response (SOAR) platform can be configured with rules to automatically analyze incoming alerts. By designing a SOAR rule to identify and drop irrelevant or duplicated notifications, the system reduces the 'noise' that analysts would otherwise have to manually triage, significantly improving efficiency and reducing alert fatigue.

Concept tested: Alert fatigue reduction using SOAR

Source: https://learn.microsoft.com/en-us/azure/sentinel/overview-soc-automation

Topics

#SOC operations#Alert fatigue#SOAR#Automation

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice