ExamGecko
Question list
Search
Search

Related questions











Question 421 - CISA discussion

Report
Export

Which of the following would be of GREATEST concern when reviewing an organization's security information and event management (SIEM) solution?

A.
SIEM reporting is customized.
Answers
A.
SIEM reporting is customized.
B.
SIEM configuration is reviewed annually
Answers
B.
SIEM configuration is reviewed annually
C.
The SIEM is decentralized.
Answers
C.
The SIEM is decentralized.
D.
SIEM reporting is ad hoc.
Answers
D.
SIEM reporting is ad hoc.
Suggested answer: C

Explanation:

The greatest concern that the IS auditor should have when reviewing an organization's security information and event management (SIEM) solution is that the SIEM is decentralized. This is because a decentralized SIEM can pose challenges for collecting, correlating, analyzing and reporting on security events and incidents from multiple sources and locations. A decentralized SIEM can also increase the complexity and cost of maintaining and updating the SIEM components, as well as the risk of inconsistent or incomplete security monitoring and response. The IS auditor should recommend that the organization adopts a centralized or hybrid SIEM architecture that can provide a holistic and integrated view of the security posture and activities across the organization.The other findings are not as concerning as a decentralized SIEM, because they can be addressed by implementing best practices and standards for SIEM reporting and configuration.Reference:CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.4

asked 18/09/2024
Robert Calderon
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first