INCIDENT DETECTION AND VERIFICATION
Do detection tools have limitations in their detection capabilities?
Detection tools have limitations in their detection capabilities. Detection tools are an important part of incident detection and response, but they cannot detect everything. Additional methods of detection can be used to improve coverage and accuracy.
Why do security analysts refine alert rules? Select two answers.
Security analysts refine alert rules to improve the accuracy of detection technologies and reduce false positive alerts. Rules are adjusted to match the activity intended to be detected.
Fill in the blank: _____ involves the investigation and validation of alerts.
Analysis involves the investigation and validation of alerts.
What are some causes of high alert volumes? Select two answers.
Misconfigured alert settings and broad detection rules are some causes of high alert volumes.
What actions do security analysts perform during the Detection and Analysis phase of the NIST Incident Response Lifecycle? Select two answers.
Security analysts investigate and validate security alerts during the Detection and Analysis phase of the NIST Incident Response Lifecycle.
Ready to test your recall?
Do detection tools have limitations in their detection capabilities?
How confident are you in this answer?