hardMultiple Select
CS0-003 Practice Question: A SOC wants to measure whether alert enrichment…
A SOC wants to measure whether alert enrichment is improving operations. Which metrics are useful? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between metrics that measure operational improvement (e.g., triage time reduction) versus metrics that measure data completeness (e.g., enrichment field population), and candidates may mistakenly choose a storage-related metric that seems tangentially related to operations but is irrelevant to enrichment effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduction in analyst triage time for enriched alerts
A primary goal of alert enrichment is to reduce the time analysts spend investigating alerts. By automatically populating context such as asset owner, criticality, and vulnerability data, enrichment eliminates manual lookup steps, directly lowering mean time to triage (MTTT). This metric quantifies operational efficiency gains from enrichment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reduction in analyst triage time for enriched alerts
Why this is correct
A primary objective of alert enrichment is to accelerate the incident response lifecycle by automatically appending contextual data, such as threat intelligence or host details, to incoming alerts. Measuring a decrease in the mean time to triage (MTTT) directly quantifies the operational efficiency gained from this automated enrichment process, proving that analysts can make faster, more informed decisions.
- ✓
Percentage of enriched alerts with asset owner and criticality populated
Why this is correct
For enrichment to be effective, the appended metadata must be actionable and complete. Tracking the percentage of alerts populated with critical context, such as asset ownership and business impact, directly measures the quality and completeness of the CMDB integration. This ensures analysts can immediately prioritize high-risk systems without manual lookup.
- ✗
Amount of storage used by desktop screenshots
Why it's wrong here
While desktop screenshots might be captured during forensic investigations or endpoint monitoring, tracking their storage consumption is a capacity planning metric rather than a security operations KPI. This metric does not provide any insight into the quality, speed, or effectiveness of the alert enrichment pipeline within a SIEM or SOAR platform.
- ✗
Number of unused browser bookmarks
Why it's wrong here
Browser bookmarks are localized user-interface shortcuts managed individually by analysts and do not correlate with security telemetry or automated enrichment workflows. Monitoring unused bookmarks fails to yield any actionable data regarding SOC performance, detection engineering, or the operational value of ingested threat intelligence.
Go deeper
Related to this question
Learn chapter
Security Metrics and KPIs
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.