ExamGecko
Question list
Search
Search

Related questions

Question 92 - CISA discussion

Report
Export

An IS auditor finds the log management system is overwhelmed with false positive alerts. The auditor's BEST recommendation would be to:

A.
establish criteria for reviewing alerts.
Answers
A.
establish criteria for reviewing alerts.
B.
recruit more monitoring personnel.
Answers
B.
recruit more monitoring personnel.
C.
reduce the firewall rules.
Answers
C.
reduce the firewall rules.
D.
fine tune the intrusion detection system (IDS).
Answers
D.
fine tune the intrusion detection system (IDS).
Suggested answer: D

Explanation:

Fine tuning the intrusion detection system (IDS) is the best recommendation to reduce the number of false positive alerts that overwhelm the log management system, because it can help adjust the sensitivity and accuracy of the IDS rules and signatures to match the network environment and traffic patterns.Establishing criteria for reviewing alerts, recruiting more monitoring personnel, and reducing the firewall rules are not effective solutions to address the root cause of the false positive alerts, but rather ways to cope with the consequences.Reference:CISA Review Manual (Digital Version), Chapter 5, Section 5.4.3

asked 18/09/2024
Reinhard KOhl
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first