mediumMultiple Choice
CISM Practice Question: A large enterprise with a centralized Security…
A large enterprise with a centralized Security Information and Event Management (SIEM) system is experiencing a high volume of false positive alerts. The security team is overwhelmed and has started to ignore many alerts. During a recent incident, a critical alert indicating lateral movement by an attacker was missed because it was buried among hundreds of false positives. The incident escalated significantly before it was discovered. The CISO has asked the incident response manager to recommend improvements to prevent this from happening again. What should the manager recommend as the primary action?
⚠ Common exam trap
CISM often tests the misconception that more staff or higher thresholds solve alert fatigue — the correct answer is almost always to improve detection quality through tuning, not to blunt or bypass the detection mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tune SIEM rules to eliminate known false positives
The root cause of the missed critical alert is alert fatigue caused by a high volume of false positives. Tuning SIEM correlation rules to eliminate known false positives directly reduces noise while preserving detection of genuine threats like lateral movement. This is the primary, sustainable action that improves signal-to-noise ratio without weakening detection coverage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase all alert thresholds to reduce volume
Why it's wrong here
Raising thresholds suppresses the low-fidelity signals that correlate into lateral-movement detection, so the missed critical alert recurs. It is tempting because it directly reduces the flood overwhelming analysts, and it would be correct for a specific noisy rule after baselining rather than as a blanket change.
- ✓
Tune SIEM rules to eliminate known false positives
Why this is correct
Tuning SIEM rules to eliminate known false positives reduces alert volume so genuine detections, such as the missed lateral movement alert, are no longer buried. This directly addresses the root cause of analyst fatigue and satisfies the primary improvement requirement, restoring trust in the monitoring capability.
- ✗
Hire additional security analysts to handle the load
Why it's wrong here
Adding analysts scales manual triage without reducing the false-positive volume, so the buried lateral-movement alert recurs. It is tempting because headcount genuinely helps when alert quality is sound and volume is simply high; here the SIEM's detection logic, not staffing capacity, is the failing control.
- ✗
Disable all non-critical alert categories
Why it's wrong here
Disabling non-critical categories removes detection coverage entirely, so genuine attacks in those categories go unseen rather than being triaged. It is tempting because it immediately cuts alert volume, and it would be right only for categories proven, through tuning, to carry no detection value.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.