Case 048927 · Blue team / DFIR · L2 Practitioner
Alert Triage
Practise as: Explain it · Interview
Interview questionAn alert fires in the SIEM. How do you triage it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Validate: read the raw event, not just the rule name; check if it is a true positive or known benign activity.
- Enrich: asset criticality, user role, IP/hash reputation, and prior alerts on the same host or account.
- Scope: pivot on user, host, hash and parent process to find related activity before and after the alert.
- Prioritize by impact and confidence; escalate with a clear summary of what, where, when and evidence.
If the interviewer pushes back
- How do you reduce alert fatigue without creating blind spots?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.