skip to content

In a tiered SOC, which alerts may a tier-1 analyst close unaided and which must go to tier-2?

level: juniorimportance: must knowfreq 72%

answer

  1. authority is written, not felt
  2. playbook coverage decides, not seniority
  3. attempt versus adversary success
  4. closing is the irreversible call
  5. no criterion means escalate

basics

~20 s

Tier-1 closes only what a written playbook fully covers: expected activity and known false-positive patterns. Anything the playbook does not cover, anything suggesting the adversary succeeded rather than merely tried, and anything on a critical asset goes to tier-2.

solid answer

~50 s

Tier is an authority boundary written down in advance, not a measure of how clever someone is. Tier-1 may reach and act on a verdict when a documented playbook covers the alert end to end: the lookups are named, the benign explanations enumerated, and the distinguishing evidence available to tier-1. That covers the two honest closes — a false positive, where the rule was wrong about maliciousness, and a benign true positive, where the behaviour happened and was authorised. Everything else escalates: no playbook, a playbook whose steps ran out while the case still looks odd, evidence that the adversary got what they were reaching for rather than attempted it, a crown-jewel asset or privileged account, or a case needing an action tier-1 may not take. Closing is the hard-to-reverse decision — nobody reopens a closed alert — so it needs the stronger justification, not the weaker one.

go deeper

for a junior

Be ready to state, in one sentence, when you may close an alert yourself and when you must pass it on, and to name the three dispositions: false positive, benign true positive, true positive.

for a middle

Explain why the burden of proof sits on the close rather than the escalation, and give escalation criteria a tired analyst can actually apply from what is on screen.

for a senior

Show how you keep the boundary honest in production: playbook coverage as the real constraint, watching for closes that speed up under queue pressure, and granting actions as deliberately as you grant conclusions.

for a principal

Own the trade the tier model makes — throughput and a hiring pipeline bought with lost context at every handover — and be able to say when your SOC has outgrown it.

## What a "tier" actually is A tier is a written statement of which conclusions a person may reach, and which actions they may take, **without a second pair of eyes**. It is not a seniority label and it is not a difficulty rating. Two analysts with identical skill can sit at different tiers in two SOCs because the two organisations wrote different boundaries. This matters in an interview because the weak answer is "tier-1 does easy alerts, tier-3 does hard ones", which gives an interviewer nothing to test. The boundary exists because a SOC has to make many decisions per shift with very few people who can make all of them. Tiering trades depth for throughput: it lets you hire people who cannot yet work a whole case, and it protects the scarce senior from a queue. ## The three dispositions, and why the distinction is load-bearing - **False positive** — the detection was wrong about maliciousness. The thing it claimed happened either did not happen, or does not mean what the rule assumed. - **Benign true positive** — the behaviour genuinely happened, and it was authorised or expected. A backup account really did read every file share; an administrator really did run a remote command. - **True positive** — the behaviour happened and it is unauthorised. Tier-1 authority normally covers the first two, and only where the playbook names the evidence that separates them. A candidate who says "tier-1 handles false positives" has missed that most tier-1 closes are benign true positives, which are harder, because you have to establish that a real action was authorised rather than that nothing happened. ## What a good escalation criterion looks like Criteria have to be checkable by the person applying them at 03:00, not by the person who wrote them at a whiteboard. Usable ones look like: - **No playbook exists for this detection** — escalate. "Use your judgment" is not a criterion; it is the absence of one. - **The playbook ran out and the case is still open** — escalate, with the negative results attached. - **Evidence of success rather than attempt** — a failed authentication burst is an attempt; one success after that burst is a different case. - **Asset or identity class** — domain controllers, identity providers, build systems, privileged and service accounts. - **The required action exceeds tier-1's rights** — if resolving the case needs a host isolated, an account disabled or a session revoked and tier-1 may not do it, the case is not tier-1's to hold. - **Multiple related alerts on the same host, account or time window** — the pattern is a different finding from any single alert in it. Notice that every one of these can be answered yes or no from what is on the screen. ## The asymmetry candidates get backwards Escalating a benign alert costs a tier-2 analyst some minutes. Closing an intrusion costs you the dwell time until somebody else finds it — often an outsider. So the two errors are not symmetric, and the burden of proof sits on the **close**, not on the escalation. That said, a tier-1 who escalates everything has quietly abolished tier-1: the queue simply moves up a floor, tier-2 saturates, and the escalations stop being read carefully. The fix for over-escalation is more playbook coverage and better enrichment, never a rule that says "escalate less". The reverse failure is the dangerous one: a tier-1 under queue pressure learns that closing keeps the numbers healthy and nobody ever comes back to complain. A closed alert generates no feedback, which is exactly why closing is the decision that needs the written authority. ## What tier-2 and tier-3 add Tier-2 is usually granted deeper investigation — pivoting across data sources, pulling artefacts from the host, correlating across cases — and a broader set of actions. Tier-3 typically covers the judgments that cannot be reduced to a playbook at all: whether a set of findings amounts to an intrusion worth escalating into the incident process, and hands-on forensic work. Whether an intrusion is formally **declared**, and by whom, is a separate authority again, sitting in the incident-response process rather than in the triage queue. ## The answer that impresses Say that the boundary is written, that it is expressed as checkable criteria rather than judgment, that it covers actions as well as conclusions, and that when the criteria are silent the default is escalate. Then add the honest caveat: the boundary is only real if somebody keeps the playbooks current, because a tier model with stale playbooks is a model where tier-1 closes on vibes and the escalation criteria describe a SOC that no longer exists.

  • A tier-1 analyst escalates almost everything 'to be safe'. What does that cost you?
    It abolishes tier-1 without saying so. The queue moves up one floor, tier-2 saturates, and escalations stop being read carefully — which is worse than the original problem, because the missed case is now buried in a pile that looks like it was reviewed. Treat it as a symptom of missing playbook coverage or thin enrichment, and fix that, rather than telling the analyst to escalate less.
  • Does closing an alert need more evidence than escalating it, or less?
    More. Escalating is reversible — a second analyst looks and may close it in a minute. Closing is terminal: no one reopens a closed alert, and it generates no feedback signal, so a wrong close is invisible until an outsider tells you about the intrusion. That asymmetry is why unaided close authority is the thing a tier model actually rations.
  • The playbook's steps all completed and the alert still looks odd. What should tier-1 do?
    Escalate, and say exactly that. Record every step that was run and what each returned, including the negative results, and state plainly which question is still unanswered. 'Playbook complete, still unexplained' is a legitimate and useful escalation reason; silently closing because the checklist ran out is the failure mode the tier boundary exists to prevent.

It works like a triage nurse's standing orders: they may discharge the cases the protocol names and must call a doctor for everything else. The limit is written on a card, not judged in the moment.

saying these in an interview costs you the question

  • Says tier is about the analyst's seniority, not written authority
  • Thinks tier-1 only ever closes false positives
  • Treats closing as cheaper and easier than escalating
  • Offers 'use your judgment' as an escalation criterion
  • Closes anything the endpoint agent already blocked
  • Cannot distinguish an attempt from evidence of success

context