hardMultiple Select
CISA Practice Question: Has implemented a database activity monitoring…
An organization has implemented a database activity monitoring (DAM) solution. Which of the following are BEST practices for tuning the DAM to reduce false positives? (Choose TWO.)
⚠ Common exam trap
Candidates often think increasing sensitivity (Option C) improves detection, but it actually amplifies false positives, whereas the correct approach is to establish a baseline (Option E) and exclude known benign activities (Option A).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement exclusions for routine maintenance activities
Option A is correct because routine maintenance activities such as backups, index rebuilds, and batch jobs generate large volumes of legitimate database traffic that would otherwise trigger alerts; creating exclusions or allowlists for these known-good operations directly reduces false positives without weakening detection of anomalous activity. Option E is correct because establishing a baseline of normal user behavior (typical query patterns, access times, source hosts, and data volumes) lets the DAM distinguish genuine deviations from benign activity, which is the foundational tuning technique for reducing false positives. Option B is incorrect because alerting on all database queries produces overwhelming noise rather than reducing false positives. Option C is incorrect because increasing detection rule sensitivity makes rules fire more easily, which increases false positives. Option D is incorrect because real-time-only review is an operational workflow choice, not a tuning practice, and does not by itself reduce false positives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement exclusions for routine maintenance activities
Why this is correct
Routine maintenance generates predictable, legitimate database activity that otherwise triggers alerts. Excluding these known operations removes noise at the source, directly reducing false positives without weakening detection of genuinely anomalous behaviour, which is the tuning goal the stem specifies.
- ✗
Enable alerts for all database queries
Why it's wrong here
Alerting on every query floods analysts with benign activity, so genuine anomalies are buried and false positives rise — the opposite of tuning. Broad alerting suits initial baselining or a low-traffic test database, not a production DAM where thresholds and filters must be refined.
- ✗
Increase the sensitivity of all detection rules
Why it's wrong here
Raising sensitivity across every rule widens the detection envelope, so benign activity matches more patterns and false positives increase rather than fall. It is tempting because higher sensitivity does catch more genuine violations, which suits high-risk, tightly monitored databases where missing an event outweighs alert volume.
- ✗
Review alerts in real-time only
Why it's wrong here
Reviewing alerts only in real time leaves no opportunity to correlate events, establish baselines or spot patterns across a longer window, so benign activity is misjudged as malicious. It is tempting because real-time monitoring genuinely suits detecting active intrusions, where immediate response matters more than reducing false positives.
- ✓
Define a baseline of normal user behavior
Why this is correct
Establishing a baseline of normal user behaviour lets the DAM distinguish genuine deviations from expected activity. Alerts then fire only on statistically abnormal actions, directly reducing false positives, which is the tuning objective the stem requires.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.