I'm not a fan of option C. Treating every alert as high level? That's like trying to put out a campfire with a fire hose. Talk about overkill. Give me some contextual data any day!
D all the way, baby! Ingesting that context data is the key to unlocking the secrets of the false positive realm. Plus, it's way more fun than, like, not trusting your security devices (B). Where's the challenge in that?
I don't know, man. Keeping the default rules (A) sounds like a recipe for disaster. You gotta customize that stuff, you know? But D is probably the safest bet.
I was thinking C at first, but that seems a bit heavy-handed. Treating every alert as high level would just create more work for us. D is definitely the way to go.
Hmm, I'm pretty sure the answer is D. Ingesting the context data seems like the best way to reduce false positives. Anything that gives you more information to work with is a win in my book.
Desmond
2 months agoJanine
1 months agoAshlyn
2 months agoVeronique
2 months agoRonny
3 months agoTess
1 months agoLemuel
1 months agoJules
1 months agoJacquline
2 months agoFelicia
3 months agoEva
3 months agoTrina
3 months agoCeola
3 months agoDevorah
3 months agoSantos
3 months agoJosphine
3 months agoBobbie
3 months ago