1. Review each alert's details. Mark as TRUE positive: the SQLi payload in a URL, the off-hours admin login from a new country, and the mass file-encryption burst. Mark as FALSE positive: the scheduled backup job and the known vulnerability scanner from the security team's IP. Why: true positives show attacker behavior; false positives are expected/benign operations.
2. Submit; when every alert is classified correctly the flag is shown.
Lesson: good triage weighs context (who/when/where) to cut noise.