mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. ``` SIEM Alert: High Severity Rule: Multiple Failed Logins Threshold: 10 failures in 5 minutes Triggered at: 2024-03-15 14:23:45 Source IP: 192.168.1.100 Target: DC01 Event Count: 15 failures in 4 minutes ```
Refer to the exhibit. The SIEM alert triggered, but the security team did not respond because they were investigating another incident. What is the BEST way to prevent such monitoring gaps in the future?
⚠ Common exam trap
Watch out — candidates often choose 'Hire additional security analysts' (Option B) as a capacity solution, but the question specifically tests the concept of operational resilience through automated failover, not just staffing levels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure automatic escalation to a secondary response team if the alert is not acknowledged within a set time.
It directly addresses the monitoring gap caused by analyst unavailability. By configuring automatic escalation to a secondary response team if an alert is not acknowledged within a set time, the organization ensures that no alert is left unattended even when the primary team is occupied. This is a standard operational resilience control in SIEM workflows, often implemented via playbook automation or SOAR integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a ticketing system to track alert handling.
Why it's wrong here
Tracking alone does not enforce response.
- ✗
Hire additional security analysts to handle peak loads.
Why it's wrong here
Not immediate and may not be cost-effective.
- ✗
Increase the threshold to reduce false positives.
Why it's wrong here
Does not solve the response gap.
- ✓
Configure automatic escalation to a secondary response team if the alert is not acknowledged within a set time.
Why this is correct
Ensures alerts are not ignored.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.