A security team notices their IDS is generating thousands of alerts per day but analysts can only investigate 50. Which tuning strategy best addresses this alert fatigue?
-
A
Disable all low-severity rules
-
B
Implement risk-based alert prioritization and suppress known-good traffic baselines
-
C
Increase analyst headcount only
-
D
Switch from signature-based to anomaly-based detection exclusively