ExamGecko
Question list
Search
Search

Question 536 - CISM discussion

Report
Export

Which of the following presents the GREATEST risk associated with the use of an automated security information and event management (SIEM) system?

A.
Low number of false positives
Answers
A.
Low number of false positives
B.
Low number of false negatives
Answers
B.
Low number of false negatives
C.
High number of false positives
Answers
C.
High number of false positives
D.
High number of false negatives
Answers
D.
High number of false negatives
Suggested answer: D

Explanation:

A false negative is a security incident that was not detected by the SIEM system, which presents the greatest risk as it allows attackers to compromise the organization's assets and data without being noticed or stopped. A high number of false negatives can indicate that the SIEM system is not configured properly, has insufficient data sources, or lacks effective analytics and correlation rules. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Sanjiv Cumar
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first