A security analyst is reviewing logs and sees an alert for a known malware signature on an endpoint. Upon investigation, the file is identified as a false positive. What should the analyst do next?
A confirmed false positive means the signature is triggering on benign activity, so tuning the detection rule with an exception prevents recurring noise while preserving genuine detection. This addresses the alert's inaccuracy without disabling the control entirely.
Why this answer
Creating an exception in the detection rule is the correct next step because the file has been confirmed as a false positive. This action prevents the security tool from generating future alerts for the same benign file, reducing noise and allowing the analyst to focus on genuine threats. It is a standard whitelisting practice in endpoint detection and response (EDR) or antivirus systems to maintain operational efficiency without compromising security.
Exam trap
The trap here is that candidates may confuse 'false positive' with 'true positive' and choose to quarantine or escalate, failing to recognize that the correct response is to tune the detection rule to eliminate noise.
How to eliminate wrong answers
Option B is wrong because quarantining a known false positive would disrupt legitimate operations and waste resources, as the file is not malicious. Option C is wrong because escalating a confirmed false positive to management is unnecessary and bypasses the analyst's responsibility to handle routine tuning of detection rules. Option D is wrong because deleting the alert from the SIEM removes forensic evidence and audit trails; instead, the alert should be closed with a reason or suppressed via an exception rule.