Question: An organization is currently undergoing a major system upgrade, which limits the ability to make changes to its monitoring tools' detection mechanisms over the next
An organization is currently undergoing a major system upgrade, which limits the ability to make changes to its monitoring tools' detection mechanisms over the next six months. During this period, the IT team needs to manage a high volume of false positives effectively. Which of the following techniques should be prioritized to handle the volume of alerts during this transitional phase without modifying underlying detection mechanisms? Select the three best options.
AIdentifying and segregating sources of false positive indicators for further analysis
BRefining detection rules and muting alert levels
CRedirecting sudden alert "floods" to a dedicated group
DRedirecting infrastructurerelated alerts to a dedicated group
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
