CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 580


An IS auditor finds the log management system is overwhelmed with false positive alerts. The auditor's BEST recommendation would be to:

Show Answer
Correct Answer: BD

To address the issue of the log management system being overwhelmed with false positive alerts, the best recommendation is to establish criteria for reviewing alerts. This approach helps ensure that only relevant alerts are generated and reduces the number of false positives by filtering out non-critical alerts through well-defined rules and thresholds. This way, the log management system becomes more effective in identifying and alerting on actual security incidents.

Discussion

7 comments
Sign in to comment
Tsubasa1234Option: B
Jan 14, 2023

Why not B establish criteria for reviewing alerts.

oldmagicOption: B
Jun 30, 2023

B is the more sound answer here. The original question makes no mention of IDS

SRJ13Option: B
Mar 28, 2023

B. Establish criteria for reviewing alerts. Establishing criteria for reviewing alerts helps to ensure that only relevant alerts are generated and that false positive alerts are reduced. This can be accomplished by creating rules and thresholds that filter out non-critical alerts or by configuring the system to trigger alerts only when certain conditions are met. By doing so, the log management system will be able to more effectively identify and alert on actual security incidents, reducing the number of false positives.

RS66Option: D
Jul 10, 2024

D. fine tune the intrusion detection system (IDS).

shiowbahOption: D
Oct 29, 2023

D. fine tune the intrusion detection system (IDS).

shiowbah
Nov 19, 2023

B. establish criteria for reviewing alerts.

RachyOption: D
Jan 20, 2024

D is correct. CISA Review Manual (Digital Version), Chapter 5, Section 5.4.3

Yejide03Option: D
Feb 20, 2024

D. fine tune the intrusion detection system (IDS).