An analyst notices that an AI-powered detection tool is flagging legitimate administrative PowerShell scripts as malicious. Which approach should the analyst take to improve model precision?
Adding false positives to the training set allows the model to learn the boundary between legitimate admin activity and malicious PowerShell usage. This process of continuous learning improves model accuracy over time, significantly reducing the burden on the SOC by filtering out expected, non-malicious behavior from the daily alert queue.
Why this answer
Model precision is improved by incorporating false positives into the training loop. By labeling these administrative scripts correctly, the analyst provides the model with the necessary 'negative' examples to learn the nuances between legitimate management tasks and malicious activity. This reduces future noise, allowing the incident response team to focus on actual threats rather than spending time triaging recurring, known-good administrative actions that currently trigger alerts.
Exam trap
Candidates frequently suggest adjusting global thresholds or rewriting the entire detection engine, missing the direct solution of retraining the model with specific false-positive samples.