hardMultiple ChoiceObjective-mapped
CRISC Practice Question: A large financial services firm recently deployed…
A large financial services firm recently deployed a new security information and event management (SIEM) system to monitor thousands of servers, network devices, and applications. The system is generating over 1,000 alerts per hour, of which 80% are false positives. The security operations center (SOC) team is overwhelmed and has started ignoring all but the most critical alerts. As a result, a real attack recently went undetected for 48 hours. The risk manager is asked to recommend improvements. The SOC team has 12 analysts working in shifts. The SIEM is properly configured but the correlation rules are broad and noisy. The firm cannot add more staff due to budget freeze. What should the risk manager prioritize?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tune the alerting rules and adopt risk-based prioritization to filter out known false positives.
Tuning alerting rules with risk-based prioritization reduces noise and ensures the SOC focuses on true positives. Disabling low-priority alerts (A) may cause missing important events; hiring (D) is not feasible due to budget freeze; machine learning (B) is complex and still needs tuning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all low-priority alerts to reduce volume immediately.
Why it's wrong here
Disabling low-priority alerts may cause missing important events; it is not a recommended approach as it does not address the root cause of noise.
- ✗
Implement a machine learning algorithm to automatically classify alerts.
Why it's wrong here
Implementing machine learning is complex and may still require significant tuning; it is not the immediate priority given the current situation.
- ✓
Tune the alerting rules and adopt risk-based prioritization to filter out known false positives.
Why this is correct
Tuning alerting rules with risk-based prioritization directly reduces noise and ensures the SOC focuses on true positives; this is the most feasible and effective improvement.
- ✗
Request budget to hire five additional SOC analysts.
Why it's wrong here
Requesting budget to hire additional analysts is not feasible due to the budget freeze, and adding staff without reducing noise is inefficient.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization deployed a new intrusion detection system (IDS) that generates many alerts. The security team is overwhelmed and has started ignoring some alerts. What is the BEST way to address this issue?
medium- A.Implement a SIEM to filter and prioritize alerts.
- B.Deactivate the IDS until it can be properly configured.
- ✓ C.Tune the IDS to reduce false positive alerts.
- D.Hire additional security analysts to handle the alert volume.
Why C: Tuning the IDS to reduce false positive alerts directly addresses the root cause of alert fatigue: excessive noise from misconfigured or overly sensitive detection rules. By adjusting thresholds, signatures, and exclusion lists, the security team can focus on genuine threats without being overwhelmed, which is a core risk monitoring and reporting practice.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.