A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?
Choose an answer
Tap an option to check your answer.
Correct answer: Tuning.
Why this is the answer
Tuning involves adjusting security tools (like SIEMs or IDS/IPS) to reduce false positives and focus on actual threats. When a SOC determines that previously flagged activity is normal, they tune the system to ignore similar future events, preventing unnecessary alerts. Aggregating combines data from multiple sources, often for analysis, not for ignoring specific activities. Quarantining isolates a suspicious file or system to prevent further harm, which is a response to a threat, not a method for ignoring normal activity. Archiving stores old data for long-term retention, which is unrelated to filtering live alerts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed