Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing an organization's implementation of a security information and event management (SIEM) system. The auditor wants to assess whether the SIEM is effectively supporting incident detection and response. Which TWO of the following are the MOST important factors for the auditor to evaluate? (Choose two.)

⚠ Common exam trap

The trap here is focusing on technical specifications such as storage or vendor reputation instead of the operational factors that determine whether the SIEM actually detects and enables response to incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The completeness of log sources and the timeliness of log ingestion from critical systems.

The effectiveness of a SIEM for incident detection and response hinges on two operational pillars: comprehensive, timely log ingestion from critical systems, and well-tuned correlation rules supported by defined investigation and escalation procedures. Without complete and timely data, detection is blind; without tuning and response processes, alerts are noise. Storage capacity, vendor reputation, and physical security are secondary considerations for this specific audit objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The completeness of log sources and the timeliness of log ingestion from critical systems.

    Why this is correct

    A SIEM's detection capability depends on the breadth and timeliness of the data it ingests. If critical systems such as firewalls, domain controllers, and databases are not forwarding logs, or if ingestion is delayed, the SIEM cannot correlate events or alert on emerging threats in real time. Evaluating log source coverage and ingestion latency is therefore fundamental to assessing whether the SIEM can effectively support incident detection.

  • ✗

    The brand reputation of the SIEM vendor and the number of industry awards it has received.

    Why it's wrong here

    Vendor reputation and awards are not reliable indicators of whether the SIEM is effectively implemented and operated in this specific environment. A reputable product can be poorly configured or underutilized. The auditor should focus on operational effectiveness—log coverage, tuning, and response procedures—rather than marketing recognition, which does not reflect the organization's actual detection and response capabilities.

  • ✗

    The physical security of the SIEM server room and the biometric access controls at the data center.

    Why it's wrong here

    Physical security of the SIEM infrastructure is important for protecting the system from tampering, but it is not among the most critical factors for assessing whether the SIEM supports incident detection and response. The primary evaluation should focus on whether the SIEM receives complete and timely data and whether alerts are properly tuned, investigated, and escalated. Physical controls are a separate, though related, audit area.

  • ✓

    The process for tuning correlation rules and the procedures for investigating and escalating alerts.

    Why this is correct

    Even a well-fed SIEM produces value only if its correlation rules are tuned to the environment and if alerts are triaged, investigated, and escalated through defined procedures. Without tuning, the system generates excessive false positives or misses true threats. Without investigation and escalation workflows, alerts are ignored. Evaluating these operational processes is essential to determine whether the SIEM actually supports incident detection and response.

  • ✗

    The total storage capacity of the SIEM and the compression ratio of archived logs.

    Why it's wrong here

    Storage capacity and compression affect retention and cost, but they do not determine whether the SIEM effectively detects and responds to incidents. A SIEM with ample storage but poor log coverage or untuned rules will still fail to detect threats. While retention is important for forensic investigations and compliance, it is secondary to the factors that directly enable detection and response.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.