A security operations center (SOC) team wants to reduce alert fatigue by ensuring that low-severity threat events do not inundate their SIEM, while ensuring high-severity exploit attempts trigger immediate escalation. How should the administrator configure the security profiles to manage this?
Correct. Administrators can configure custom actions per severity level within security profiles to handle alerts appropriately.
Why this answer
Security profiles allow administrators to customize the action (such as alert, drop, reset-both) taken based on threat severity or specific threat IDs.