Courseiva
hardMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: A large organization has implemented a Security…

A large organization has implemented a Security Operations Center (SOC) with a tiered incident response model. Tier 1 analysts triage alerts and escalate confirmed incidents to Tier 2 for deeper analysis. Recently, the SOC has been overwhelmed by a high volume of low-severity alerts from endpoint detection and response (EDR) tools, causing delays in handling true positive incidents. The SOC manager wants to reduce alert fatigue without missing critical threats. Which of the following strategies would be MOST effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement automated playbooks for low-severity alerts to perform initial investigation and closure if benign.

The most effective strategy because implementing automated playbooks for low-severity alerts allows the SOC to handle high-volume, low-risk events without human intervention. Automation can triage, investigate, and close benign alerts, reducing alert fatigue and freeing Tier 1 analysts to focus on true positives. Option A reverses the tiered model and would overwhelm Tier 2 without addressing root cause. Option B only adds more analysts to deal with symptoms, not the root cause of volume. Option D risks missing critical threats by disabling rules entirely, which could lead to security gaps. Automated playbooks strike the right balance between efficiency and security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require Tier 2 analysts to review all alerts before Tier 1.

    Why it's wrong here

    Creates a bottleneck and increases response time for all alerts.

  • Increase the number of Tier 1 analysts to handle the volume.

    Why it's wrong here

    Increases cost without reducing alert volume; may not be sustainable.

  • Implement automated playbooks for low-severity alerts to perform initial investigation and closure if benign.

    Why this is correct

    Reduces manual triage and allows analysts to focus on critical threats.

  • Disable all low-severity alert rules in the EDR.

    Why it's wrong here

    Risks missing threats that manifest as low-severity alerts before escalation.

About these practice questions

One of 976 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.