Courseiva

CRISC Information Technology and Security Practice Question

A financial services firm is deploying a security information and event management (SIEM) platform. The risk practitioner is asked to advise on how to keep the alert pipeline trustworthy so that detection and response decisions rest on reliable data. Which of the following is the MOST important control to prioritize?

⚠ Common exam trap

The trap here is equating more logging and better tuning with trustworthy detection, when the real dependency is the integrity and time ordering of the events themselves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Protect the integrity and time synchronization of log sources and the collection path end to end.

A SIEM is only as reliable as the events it receives, so the priority is ensuring those events are authentic and consistently time-stamped. Protecting log sources and the transport path against tampering, and synchronizing clocks, prevents attackers from hiding activity or fabricating evidence. Volume, tuning, and packet capture all matter operationally but none of them restores confidence in data that could have been altered.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable full packet capture retention for at least ninety days across all network segments.

    Why it's wrong here

    Full packet capture is expensive to store and analyze and is usually reserved for targeted investigation rather than continuous monitoring. It also sits downstream of the logging pipeline, so it does not protect event integrity or time ordering. Retaining packets broadly consumes budget without fixing the trustworthiness problem the practitioner was asked to solve.

  • ✗

    Tune correlation rules to reduce the number of alerts reaching the analyst queue.

    Why it's wrong here

    Alert tuning improves analyst efficiency and reduces fatigue, which is valuable, but it operates on data already collected. If the underlying events are tampered with or misordered in time, even well-tuned rules produce misleading conclusions. Tuning addresses signal quality, not the integrity of the evidence feeding the rules.

  • ✓

    Protect the integrity and time synchronization of log sources and the collection path end to end.

    Why this is correct

    Detection and response decisions depend on logs being authentic and correctly ordered in time. If an attacker can alter logs in transit or manipulate host clocks, correlation breaks down and incidents can be hidden or fabricated. Securing the collection path and enforcing consistent time synchronization is therefore the foundational control for a trustworthy pipeline.

  • ✗

    Maximize the number of log sources ingested so that no event type is missed.

    Why it's wrong here

    Ingesting every available source increases volume, cost, and alert noise without guaranteeing integrity of the data received. A compromised or misconfigured source can inject false or incomplete events, and analysts may drown in low-value alerts. Coverage breadth matters, but it is not the control that makes the pipeline trustworthy for decision making.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.