A SOC deploys an AI assistant that summarises and prioritises incoming alerts to speed up triage. During a busy shift, an analyst notices the assistant consistently ranks alerts from one noisy scanner as top priority while burying a credential-stuffing pattern lower down. What is the analyst's best response?
- AApply analyst judgement to re-prioritise the credential-stuffing alerts and report the ranking flaw for tuning. Correct
- BDisable all AI triage assistance permanently, as it has proven unable to prioritise alerts correctly.
- CContinue to accept the assistant's ranking, since the tool processes more context than a human analyst can.
- DDelete the noisy scanner alerts from the queue so the assistant stops ranking them highly.
Why A is correct: Correct: AI triage augments the analyst, so the analyst overrides the flawed ranking on the evidence and feeds the issue back so the tool improves.
Why B is wrong: Tempting after a visible miss, but a single prioritisation error does not justify removing a tool that reduces overall triage load; the fix is oversight, not abandonment.
Why C is wrong: Tempting because AI can weigh more signals, but blind acceptance of a demonstrably skewed ranking lets a real threat sit unactioned.
Why D is wrong: Tempting as a quick way to clean the queue, but deleting source alerts destroys evidence and does not address the assistant's flawed weighting.