Exercise 2: The Real Cost of Over-Flagging Every Odd Symptom — Possible Solution ==================================================================== WHAT THIS CHAPTER SAYS ------------------------------ Per this chapter, "treating every odd symptom as a full security incident produces the same problem Chapter 4 warned against for over-verification: alert fatigue, wasted investigation time, and a support process people learn to route around." WHY THIS IS A COST, NOT JUST INEFFICIENCY ------------------------------ "Extra careful" implies the only downside is spending a bit more effort than strictly necessary, with no real harm done. Alert fatigue is a different, worse outcome: when every ticket gets treated as a potential incident, the genuinely serious ones stop standing out from the routine over-flagged ones. The people responsible for responding become desensitized precisely because nothing they're shown ever turns out to be routine - which erodes their ability to respond quickly to the cases that actually matter. THE DIRECT PARALLEL TO CHAPTER 4 ------------------------------ This is the same failure mode Chapter 4 identified for uniform maximum verification: treating everything the same way erases the very distinction the process exists to draw. Applied here, if every odd symptom triggers full incident escalation, escalation stops meaning "this one is different" - it just becomes routine noise, and the signal it's supposed to carry is lost. WHY "PEOPLE LEARN TO ROUTE AROUND IT" IS THE WORST PART ------------------------------ Beyond wasted time, over-flagging trains both the technician raising tickets and whoever receives escalations to stop taking the process seriously - exactly the same "quietly bypassed process provides zero protection" problem the Chapter 4 exercise solutions already established. A costly process that gets ignored is worse than a lighter process that's actually followed. WHY THIS WORKS AS AN ANSWER ------------------------------ It quotes the chapter's own reasoning, explains why alert fatigue is a genuine cost rather than mere inefficiency, and connects it directly to the identical failure mode already established in Chapter 4 around over-verification.