Courseiva
hardMultiple Choice

Alert Verification and Correlation — Key First Steps in Incident Response

A security operations center (SOC) analyst receives an alert from the SIEM indicating a potential command and control (C2) communication. The alert is based on a signature that matches known C2 traffic. What is the MOST appropriate next step?

⚠ Common exam trap

CISM often tests the impulse to take immediate containment action (block, escalate, scan) instead of first validating the alert through correlation, which is the correct triage step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the alert by correlating with other log sources

A SIEM alert based on a signature match is an indicator, not confirmed compromise; signature-based detection can produce false positives. The most appropriate next step is to verify the alert by correlating with other log sources — such as DNS logs, proxy logs, endpoint telemetry, and NetFlow — to determine whether the C2 communication is real and to understand its scope. Only after validation should the analyst escalate, block, or remediate, ensuring incident response resources are not wasted on false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block the destination IP address at the firewall

    Why it's wrong here

    Blocking the destination IP at the firewall acts before triage confirms the alert is a true positive, and C2 infrastructure rotates addresses rapidly, so the block may be evaded while legitimate traffic is disrupted. It is tempting because containment is a valid response once an incident is verified.

  • ✗

    Escalate the alert to the incident response team immediately

    Why it's wrong here

    Escalating immediately skips the analyst's triage step of validating whether the signature match is a true positive, so the incident response team receives unverified data. Escalation is correct once triage confirms genuine C2 activity requiring coordinated containment.

  • ✓

    Verify the alert by correlating with other log sources

    Why this is correct

    Correlating the signature match with other log sources confirms whether the C2 traffic is genuine or a false positive, satisfying the need to validate before escalation. This verification step distinguishes malicious beaconing from legitimate outbound connections prior to containment.

  • ✗

    Perform a full antivirus scan on all endpoints

    Why it's wrong here

    A full antivirus scan across all endpoints addresses file-based malware, not the network C2 channel the SIEM signature flagged, and it is slow and disruptive. Scanning is appropriate when triage indicates malware execution or persistence requiring host-level remediation.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security operations center receives an alert from an IDS indicating possible command and control traffic. The analyst is unsure if it's a true positive. Which combination of actions should be taken first?

hard
  • A.Disable the IDS signature to prevent further alerts.
  • B.Immediately block the source IP and escalate to the incident response team.
  • C.Conduct a full forensic analysis of the affected host.
  • ✓ D.Correlate the alert with firewall and proxy logs and review threat intelligence.

Why D: The first step in validating a potential command and control (C2) alert is to correlate the IDS event with other network logs (e.g., firewall, proxy) and threat intelligence. This helps confirm whether the traffic matches known C2 patterns (e.g., beaconing intervals, unusual DNS queries) before taking any disruptive action. Premature blocking or forensic analysis without correlation risks false positives or missing context.

Variation 2. A security analyst receives an alert indicating a potential data exfiltration from a server. Which of the following should be the FIRST step in the incident response process?

easy
  • A.Perform a forensic analysis.
  • B.Escalate to senior management.
  • C.Isolate the server from the network.
  • ✓ D.Verify the alert to confirm it is not a false positive.

Why D: The first step in the incident response process is to verify the alert to confirm it is not a false positive. Prematurely isolating the server or escalating without validation can disrupt legitimate operations and waste resources. Verification ensures that the incident response team acts on confirmed threats, aligning with the NIST SP 800-61 incident response lifecycle's detection and analysis phase.

Variation 3. A company's IDS alerts on a potential breach. The incident response team is called. What should they do immediately?

easy
  • ✓ A.Verify the alert and assess scope
  • B.Disconnect all network cables
  • C.Notify law enforcement
  • D.Reimage affected systems

Why A: The immediate priority upon receiving an IDS alert is to verify the alert's validity and assess the scope of the potential breach. This ensures the incident response team does not waste resources on false positives and can accurately determine the affected systems, data, and network segments before taking containment actions. Verification typically involves correlating the IDS signature with actual packet captures, logs, and system telemetry to confirm malicious activity.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.