When tuning a noisy QRadar rule that is generating excessive false positives, which approach is most appropriate?
-
A
Add exception conditions (such as trusted IP ranges or known safe users) to the rule's tests to filter benign activity
-
B
Delete the rule entirely to stop the false positives immediately
-
C
Lower the offense magnitude threshold so the rule stops triggering
-
D
Disable all log sources that are contributing events to the rule