How do you ignore detected activity in the future?

A security operations center determines that the malicious activity detected on a server is normal. Which of the following activities describes the act of ignoring detected activity in the future?

  1. Tuning Source Reference Answer
  2. Aggregating
  3. Quarantining
  4. Archiving

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of alert lifecycle management, specifically tuning to suppress future false-positive alerts after analysis confirms activity is benign.

Tuning is the process of adjusting security monitoring systems to reduce false positives by ignoring activity determined to be normal. Community consensus confirms tuning as the correct action when benign behavior repeatedly triggers alerts.

Some candidates choose 'None of the above' or 'Quarantining' because they confuse tuning with ignoring entirely, not realizing tuning formally adjusts detection rules to suppress known benign activity.

Community Discussion (5 comments)

jovines 👍 22
The act of ignoring detected activity in the future is described as A. Tuning. Tuning refers to the process of adjusting the configuration of a system, in this case, the security operations center’s detection systems, to reduce or eliminate the number of false positives. In this context, if the so-called “malicious activity” is determined to be normal and is expected to recur, the system can be tuned to ignore this activity in the future, preventing unnecessary alerts. Please note that while the other options (B. Aggregating, C. Quarantining, D. Archiving) are activities related to managing and responding to security events, they do not specifically apply to the scenario of ignoring detected activity in the future.
Mehsotopes 👍 10 Selected: A
Tuning is setting a monitoring system to have higher, or lower threat detection standards.
MarysSon 👍 1 Selected: A
But the real answer is E - None of the above. Tuning is an act of adjusting and optimizing a set of configurations to reduce risk, improve security, and improve performance. That is hardly ignoring. A system might ignore a symptom. but the security administrator does not. This question should be rephrased.
NONS3c 👍 3 Selected: A
" malicious activity detected on a server is normal" this is a key word it mean that we have fail positive so tuning working on fixing and improve performance or efficiency.
dbrowndiver 👍 3 Selected: A
Tuning is the process of configuring security tools and systems to reduce false positives and ensure that alerts are meaningful. It involves adjusting the parameters and rules of the detection systems to ignore certain activities that have been determined to be normal or non-threatening.Tuning is also the appropriate action to take when a particular activity has been analyzed and deemed safe, allowing the security system to ignore similar future alerts and reducing unnecessary alert fatigue.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Tuning is the process of adjusting detection rules, thresholds, and parameters in SIEM, IDS/IPS, or EDR tools so that known benign or expected activity no longer generates alerts. Once the SOC determines the activity is normal (a false positive), tuning suppresses future alerts for that pattern, reducing alert fatigue. This aligns directly with CompTIA SY0-701 objectives covering security monitoring and alert management.

Why the Other Options Are Wrong

Aggregating refers to collecting and combining logs or alerts from multiple sources into a central platform, which does not suppress future alerts. Quarantining isolates a file, host, or network segment to contain a threat, which is the opposite of ignoring benign activity. Archiving involves long-term storage of logs or data for compliance and forensic purposes, not the suppression of alerts.

Community Comment Notes

Comment [1] clearly defines tuning as adjusting configurations to eliminate false positives, which matches the scenario. Comment [3] highlights the keyword 'normal' as an indicator of a false positive that requires tuning. Comment [5] argues tuning is not 'ignoring,' but CompTIA treats tuning as the formal mechanism to suppress known benign alerts, making A the intended answer.

Official Reference

Exam Strategy

When a question describes activity being 'determined to be normal' or 'expected to recur,' look for tuning as the answer. Eliminate options that describe containment, storage, or collection, as they do not address false-positive suppression.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide