hardMultiple ChoiceObjective-mapped
ISC2 CC Practice Question: A large organization has implemented a Security…
A large organization has implemented a Security Operations Center (SOC) with a tiered incident response model. Tier 1 analysts triage alerts and escalate confirmed incidents to Tier 2 for deeper analysis. Recently, the SOC has been overwhelmed by a high volume of low-severity alerts from endpoint detection and response (EDR) tools, causing delays in handling true positive incidents. The SOC manager wants to reduce alert fatigue without missing critical threats. Which of the following strategies would be MOST effective?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement automated playbooks for low-severity alerts to perform initial investigation and closure if benign.
The most effective strategy because implementing automated playbooks for low-severity alerts allows the SOC to handle high-volume, low-risk events without human intervention. Automation can triage, investigate, and close benign alerts, reducing alert fatigue and freeing Tier 1 analysts to focus on true positives. Option A reverses the tiered model and would overwhelm Tier 2 without addressing root cause. Option B only adds more analysts to deal with symptoms, not the root cause of volume. Option D risks missing critical threats by disabling rules entirely, which could lead to security gaps. Automated playbooks strike the right balance between efficiency and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require Tier 2 analysts to review all alerts before Tier 1.
Why it's wrong here
Creates a bottleneck and increases response time for all alerts.
- ✗
Increase the number of Tier 1 analysts to handle the volume.
Why it's wrong here
Increases cost without reducing alert volume; may not be sustainable.
- ✓
Implement automated playbooks for low-severity alerts to perform initial investigation and closure if benign.
Why this is correct
Reduces manual triage and allows analysts to focus on critical threats.
- ✗
Disable all low-severity alert rules in the EDR.
Why it's wrong here
Risks missing threats that manifest as low-severity alerts before escalation.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Security operations center
A Security Operations Center (SOC) is a centralized team and facility that monitors, detects, analyzes, and responds to cybersecurity incidents across an organization's IT environment 24/7.
About these practice questions
One of 976 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.