exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 214 discussion

Actual exam question from CompTIA's CS0-003
Question #: 214
Topic #: 1
[All CS0-003 Questions]

Which of the following techniques can help a SOC team to reduce the number of alerts related to the internal security activities that the analysts have to triage?

  • A. Enrich the SIEM-ingested data to include all data required for triage
  • B. Schedule a task to disable alerting when vulnerability scans are executing
  • C. Filter all alarms in the SIEM with low seventy
  • D. Add a SOAR rule to drop irrelevant and duplicated notifications
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nap61
Highly Voted 9 months, 3 weeks ago
D. "SOAR tools frequently “bolt on” to a SIEM and trigger after an alert is generated. Instead of sending the alert to a security analyst for manual review, the alert is instead forwarded to a SOAR platform." CompTIA CS0-003 - Lesson 4A
upvoted 5 times
...
cy_analyst
Most Recent 7 months ago
Selected Answer: D
B. Schedule a task to disable alerting when vulnerability scans are executing: Disabling alerts during vulnerability scans might cause you to miss important incidents that occur during the scan. It’s also not a good practice to turn off alerts entirely.
upvoted 1 times
...
boog
10 months, 1 week ago
Selected Answer: D
In-house vuln scans can be dropped as irrelevant
upvoted 1 times
...
captaintoadyo
1 year ago
Selected Answer: D
The question does not state that the team wants to remove duplicate or low severity vulnerabilities so the only right answer that makes logical sense is answer D. in most comptia questions the answer is almost always in the answer!
upvoted 1 times
...
section8santa
1 year, 1 month ago
Selected Answer: B
When vulnerability scans or other routine security activities are executed, they can generate a large number of alerts that analysts must then sift through. By scheduling these scans and correlating their timing with a temporary suspension of alerts, the SOC can reduce the number of false positives or irrelevant alerts that analysts have to deal with. SOAR solutions can indeed help reduce the number of alerts by deduplicating and filtering out irrelevant notifications. However, without proper configuration, there is a risk of dropping alerts that might be relevant. This option is effective but not specifically tailored to internal security activities like option B. Therefore, scheduling tasks to disable alerting during known internal security activities (like vulnerability scans) is a targeted approach to reducing the number of alerts during those activities. It's important that this is done carefully to ensure that only the alerts generated by the scans are disabled and that other monitoring continues uninterrupted.
upvoted 2 times
section8santa
1 year ago
Go with D
upvoted 2 times
Kmelaun
1 year ago
you took the test?
upvoted 1 times
...
...
...
j904
1 year, 1 month ago
Selected Answer: D
It's D do not listen to tcgod unless you want to get this wrong
upvoted 3 times
...
Nishaw
1 year, 1 month ago
Selected Answer: D
D. Add a SOAR rule to drop irrelevant and duplicated notifications Implementing a Security Orchestration, Automation, and Response (SOAR) solution can help reduce the number of alerts that SOC analysts have to triage by automatically filtering out irrelevant or duplicated notifications. This can significantly reduce the noise level and allow analysts to focus on investigating and responding to genuine security incidents.
upvoted 4 times
...
tcgod666
1 year, 1 month ago
Selected Answer: B
I think answer is B since question is about Alerts related to internal security activities > better inform to soc team in advance to disable some use case to avoid alert flooding for soc analysts.
upvoted 1 times
j904
1 year, 1 month ago
I dont think thats right
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago