I'm not a fan of option C. Treating every alert as high level? That's like trying to put out a campfire with a fire hose. Talk about overkill. Give me some contextual data any day!
D all the way, baby! Ingesting that context data is the key to unlocking the secrets of the false positive realm. Plus, it's way more fun than, like, not trusting your security devices (B). Where's the challenge in that?
I don't know, man. Keeping the default rules (A) sounds like a recipe for disaster. You gotta customize that stuff, you know? But D is probably the safest bet.
I was thinking C at first, but that seems a bit heavy-handed. Treating every alert as high level would just create more work for us. D is definitely the way to go.
Hmm, I'm pretty sure the answer is D. Ingesting the context data seems like the best way to reduce false positives. Anything that gives you more information to work with is a win in my book.
Desmond
26 days agoAshlyn
10 days agoVeronique
16 days agoRonny
1 months agoJacquline
17 days agoFelicia
1 months agoEva
2 months agoTrina
2 months agoCeola
29 days agoDevorah
1 months agoSantos
2 months agoJosphine
2 months agoBobbie
2 months ago