Tune analytic logic, reduce noisy alerts, and map detections to attacker behavior.
4
Questions
80%
Pass score
+180
XP
18m 0s
Time
A good correlation rule should alert on which of the following?
Which tuning change most directly reduces false positives from admin maintenance scripts?
A detection mapped to MITRE ATT&CK is easier to explain, test, and gap-assess.
What is the term for the percentage of alerts that are actually malicious or truly actionable?
Write the defensive concept or action clearly. Administrators can configure multiple accepted answer variants.