nerdexam
CompTIA

CY0-001 · Question #43

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of machine learning (ML) system to help with triage. Which of the following…

The correct answer is C. Identifying and classifying alerts. Machine learning is best suited for analyzing large volumes of security data and distinguishing between true threats and false positives. By identifying and classifying alerts, the ML system helps the SOC prioritize incidents and reduce analyst workload.

Threat Management

Question

A security operations center (SOC) has a very high volume of logs and alerts. The manager proposes the implementation of machine learning (ML) system to help with triage. Which of the following tasks is most suitable?

Options

  • AApplying filters on specific alerts
  • BAutomatically patching vulnerable systems
  • CIdentifying and classifying alerts
  • DSummarizing the content of alerts

How the community answered

(33 responses)
  • B
    9% (3)
  • C
    88% (29)
  • D
    3% (1)

Explanation

Machine learning is best suited for analyzing large volumes of security data and distinguishing between true threats and false positives. By identifying and classifying alerts, the ML system helps the SOC prioritize incidents and reduce analyst workload.

Topics

#SOC operations#ML-based triage#alert classification#log analysis

Community Discussion

No community discussion yet for this question.

Full CY0-001 Practice