Which of the following BEST describes the 'cold start problem' in a newly deployed UEBA (User and Entity Behavior Analytics) system, and what is the practical implication for the SOC?
- A.Cold start refers to the system overheating during initial deployment and requiring hardware cooling; automated response carries no model-risk surface of its own, because SOAR actions are reversible by design: every containment step ships with an automatic rollback that restores the pre-action state, meaning a false positive costs seconds rather than availability
- B.The cold start problem means UEBA systems cannot detect insider threats and should only be used for external attackers
- C.UEBA systems need to be initialized by manually entering user behavior profiles before deployment
- D.A newly deployed UEBA system has no historical behavior baseline for users and entities, so it cannot accurately score anomalies until it observes enough normal behavior (typically 30-90 days of baseline collection); the SOC must suppress or manually review UEBA alerts during this period to avoid excessive noise