Courseiva
mediumMultiple Choice

CRISC Practice Question: Has implemented a continuous monitoring solution…

An organization has implemented a continuous monitoring solution for its critical applications. The IT team reports that the monitoring tool generates a high volume of false positives. What is the BEST course of action?

⚠ Common exam trap

The CRISC exam often tests the misconception that increasing resources (team size) or adding more controls is the best response to monitoring inefficiency, when in fact tuning existing controls is the most effective and risk-appropriate action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Refine the monitoring rules and thresholds to reduce false positives.

Refining monitoring rules and thresholds directly addresses the root cause of false positives by tuning the detection logic to better match actual risk conditions. This aligns with the CRISC principle of optimizing control efficiency rather than accepting or compensating for excessive noise. For example, adjusting anomaly detection thresholds in a SIEM like Splunk or QRadar can reduce alert volume without sacrificing coverage of genuine threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Refine the monitoring rules and thresholds to reduce false positives.

    Why this is correct

    Tuning rules and thresholds addresses the root cause: overly broad signatures or tight baselines generate noise. This restores signal quality so genuine anomalies surface, preserving the continuous monitoring objective rather than disabling alerts or ignoring findings.

  • ✗

    Disable the monitoring for applications that generate the most false positives.

    Why it's wrong here

    Disabling monitoring removes visibility entirely, so real threats in those applications go undetected — an unacceptable risk response. It tempts because suppressing the noisiest sources does cut alert volume, and would be defensible only for decommissioned or non-critical systems.

  • ✗

    Increase the size of the monitoring team to handle the alerts.

    Why it's wrong here

    Adding staff scales the manual triage of noisy alerts but leaves the detection logic unchanged, so false positives keep firing and consume the new capacity. It tempts because extra analysts do help when alert volume is legitimate and genuinely exceeds current response capacity.

  • ✗

    Implement additional detective controls for all false positive alerts.

    Why it's wrong here

    Layering detective controls onto every false positive multiplies cost and noise without correcting the rules that misclassify benign activity. It tempts because additional detective controls are the right response when a genuine detection gap exists, not when existing rules simply misfire.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.