Open cardosec

Case 048927 · Blue team / DFIR · L2 Practitioner

Alert Triage

Practise as: Explain it · Interview

Interview questionAn alert fires in the SIEM. How do you triage it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Validate: read the raw event, not just the rule name; check if it is a true positive or known benign activity.
  2. Enrich: asset criticality, user role, IP/hash reputation, and prior alerts on the same host or account.
  3. Scope: pivot on user, host, hash and parent process to find related activity before and after the alert.
  4. Prioritize by impact and confidence; escalate with a clear summary of what, where, when and evidence.

If the interviewer pushes back

  • How do you reduce alert fatigue without creating blind spots?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.