hardMultiple Choice
CRISC Practice Question: A large financial services firm recently deployed…
A large financial services firm recently deployed a new security information and event management (SIEM) system to monitor thousands of servers, network devices, and applications. The system is generating over 1,000 alerts per hour, of which 80% are false positives. The security operations center (SOC) team is overwhelmed and has started ignoring all but the most critical alerts. As a result, a real attack recently went undetected for 48 hours. The risk manager is asked to recommend improvements. The SOC team has 12 analysts working in shifts. The SIEM is properly configured but the correlation rules are broad and noisy. The firm cannot add more staff due to budget freeze. What should the risk manager prioritize?
⚠ Common exam trap
CRISC often tests whether candidates prioritize root-cause remediation (tuning rules) over quick fixes (disabling alerts) or infeasible solutions (hiring staff), so the trap is choosing an option that temporarily reduces volume but increases risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tune the alerting rules and adopt risk-based prioritization to filter out known false positives.
The core issue is that broad correlation rules generate excessive false positives, overwhelming the SOC and causing alert fatigue. Tuning the alerting rules and adopting risk-based prioritization directly addresses the root cause by reducing noise and focusing analyst attention on genuine threats. This is a sustainable, cost-effective improvement that leverages existing staff and tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all low-priority alerts to reduce volume immediately.
Why it's wrong here
Disabling low-priority alerts discards detection coverage entirely, so genuine attacks hidden among those events would go unnoticed, repeating the 48-hour miss. It is tempting because it instantly cuts volume, and would be valid for confirmed duplicate or decommissioned-source rules, but here the broad correlation rules need tuning rather than blanket suppression.
- ✗
Implement a machine learning algorithm to automatically classify alerts.
Why it's wrong here
Machine learning classification requires historical labelled data and tuning before it reduces false positives, so it cannot relieve the SOC during the current alert flood. It is tempting because ML is genuinely used for alert triage and correlation at scale, and would suit a mature detection programme with clean baseline data, not broad noisy rules needing immediate refinement.
- ✓
Tune the alerting rules and adopt risk-based prioritization to filter out known false positives.
Why this is correct
Tuning correlation rules removes the broad, noisy detections generating 80% false positives, while risk-based prioritisation focuses the 12 analysts on genuine threats. This restores detection capability without additional headcount, satisfying the budget freeze constraint that rules out hiring more staff.
- ✗
Request budget to hire five additional SOC analysts.
Why it's wrong here
Hiring is blocked by the stated budget freeze, so this cannot be actioned now and leaves the noisy rules unaddressed. It is tempting because additional analysts genuinely absorb alert volume, and would be the right long-term answer once funding returns, but the immediate priority is narrowing the broad correlation rules generating false positives.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization deployed a new intrusion detection system (IDS) that generates many alerts. The security team is overwhelmed and has started ignoring some alerts. What is the BEST way to address this issue?
medium- A.Implement a SIEM to filter and prioritize alerts.
- B.Deactivate the IDS until it can be properly configured.
- ✓ C.Tune the IDS to reduce false positive alerts.
- D.Hire additional security analysts to handle the alert volume.
Why C: Tuning the IDS to reduce false positive alerts directly addresses the root cause of alert fatigue: excessive noise from misconfigured or overly sensitive detection rules. By adjusting thresholds, signatures, and exclusion lists, the security team can focus on genuine threats without being overwhelmed, which is a core risk monitoring and reporting practice.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.