ExamGecko
Question list
Search
Search

Question 632 - CISM discussion

Report
Export

An organization's automated security monitoring tool generates an excessively large amount of falsq positives. Which of the following is the BEST method to optimize the monitoring process?

A.
Report only critical alerts.
Answers
A.
Report only critical alerts.
B.
Change reporting thresholds.
Answers
B.
Change reporting thresholds.
C.
Reconfigure log recording.
Answers
C.
Reconfigure log recording.
D.
Monitor incidents in a specific time frame.
Answers
D.
Monitor incidents in a specific time frame.
Suggested answer: B

Explanation:

Changing reporting thresholds is the best method to optimize the monitoring process when the automated security monitoring tool generates an excessively large amount of false positives. Changing reporting thresholds means adjusting the criteria or parameters that trigger the alerts, such as the severity level, the frequency, the source, or the destination of the events. Changing reporting thresholds can help to reduce the number of false positives, filter out the irrelevant or benign events, and focus on the most critical and suspicious events that require further investigation or response.

Reference=Cybersecurity tool sprawl leading to burnout, false positives: report,Security tools' effectiveness hampered by false positives

asked 01/10/2024
David Hartnett
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first