Google
PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #140
PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Question #140: Real Exam Question with Answer & Explanation
Sign in or unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to reveal the answer and full explanation for question #140. The question stem and answer options stay visible for context.
Question
A SOC uses Chronicle SIEM and wants to reduce alert fatigue without lowering detection coverage. What is the BEST strategy?
Options
- ADisable medium-severity rules
- BIncrease alert thresholds globally
- CApply risk-based alert scoring and entity correlation
- DLimit alerts to business hours
Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER to see the answer
You've previewed enough free PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER questions. Unlock PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.