Courseiva
hardMultiple Select

CISA Practice Question: Has implemented a database activity monitoring…

An organization has implemented a database activity monitoring (DAM) solution. Which of the following are BEST practices for tuning the DAM to reduce false positives? (Choose TWO.)

⚠ Common exam trap

Candidates often think increasing sensitivity (Option C) improves detection, but it actually amplifies false positives, whereas the correct approach is to establish a baseline (Option E) and exclude known benign activities (Option A).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement exclusions for routine maintenance activities

Option A is correct because routine maintenance activities such as backups, index rebuilds, and batch jobs generate large volumes of legitimate database traffic that would otherwise trigger alerts; creating exclusions or allowlists for these known-good operations directly reduces false positives without weakening detection of anomalous activity. Option E is correct because establishing a baseline of normal user behavior (typical query patterns, access times, source hosts, and data volumes) lets the DAM distinguish genuine deviations from benign activity, which is the foundational tuning technique for reducing false positives. Option B is incorrect because alerting on all database queries produces overwhelming noise rather than reducing false positives. Option C is incorrect because increasing detection rule sensitivity makes rules fire more easily, which increases false positives. Option D is incorrect because real-time-only review is an operational workflow choice, not a tuning practice, and does not by itself reduce false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement exclusions for routine maintenance activities

    Why this is correct

    Routine maintenance generates predictable, legitimate database activity that otherwise triggers alerts. Excluding these known operations removes noise at the source, directly reducing false positives without weakening detection of genuinely anomalous behaviour, which is the tuning goal the stem specifies.

  • ✗

    Enable alerts for all database queries

    Why it's wrong here

    Alerting on every query floods analysts with benign activity, so genuine anomalies are buried and false positives rise — the opposite of tuning. Broad alerting suits initial baselining or a low-traffic test database, not a production DAM where thresholds and filters must be refined.

  • ✗

    Increase the sensitivity of all detection rules

    Why it's wrong here

    Raising sensitivity across every rule widens the detection envelope, so benign activity matches more patterns and false positives increase rather than fall. It is tempting because higher sensitivity does catch more genuine violations, which suits high-risk, tightly monitored databases where missing an event outweighs alert volume.

  • ✗

    Review alerts in real-time only

    Why it's wrong here

    Reviewing alerts only in real time leaves no opportunity to correlate events, establish baselines or spot patterns across a longer window, so benign activity is misjudged as malicious. It is tempting because real-time monitoring genuinely suits detecting active intrusions, where immediate response matters more than reducing false positives.

  • ✓

    Define a baseline of normal user behavior

    Why this is correct

    Establishing a baseline of normal user behaviour lets the DAM distinguish genuine deviations from expected activity. Alerts then fire only on statistically abnormal actions, directly reducing false positives, which is the tuning objective the stem requires.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.