CompTIA CySA+ CS0-003 Practice Question
A security operations center (SOC) is experiencing a higher than usual volume of alerts. The team needs to ensure that critical incidents are not missed. Which action BEST helps prioritize and manage the alert volume effectively?
Implement a tiered alerting system that categorizes alerts based on severity.
Disable low-priority alerts to reduce overall alert volume.
Deploy automated responses to reduce manual intervention for all alerts.
Increase the thresholds for alert generation in the SIEM solution.