mediumMultiple Choice
CRISC Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit. ``` SIEM Alert: High Severity Rule: Multiple Failed Logins Threshold: 10 failures in 5 minutes Triggered at: 2024-03-15 14:23:45 Source IP: 192.168.1.100 Target: DC01 Event Count: 15 failures in 4 minutes ```
Refer to the exhibit. The SIEM alert triggered, but the security team did not respond because they were investigating another incident. What is the BEST way to prevent such monitoring gaps in the future?
⚠ Common exam trap
Watch out — candidates often choose 'Hire additional security analysts' (Option B) as a capacity solution, but the question specifically tests the concept of operational resilience through automated failover, not just staffing levels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure automatic escalation to a secondary response team if the alert is not acknowledged within a set time.
It directly addresses the monitoring gap caused by analyst unavailability. By configuring automatic escalation to a secondary response team if an alert is not acknowledged within a set time, the organization ensures that no alert is left unattended even when the primary team is occupied. This is a standard operational resilience control in SIEM workflows, often implemented via playbook automation or SOAR integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a ticketing system to track alert handling.
Why it's wrong here
A ticketing system records alerts after someone picks them up; it does not notify anyone when an alert is ignored during another investigation. Ticketing suits audit trails and workload reporting, not real-time escalation. The gap here is unactioned alerts, which requires automated escalation or on-call routing.
- ✗
Hire additional security analysts to handle peak loads.
Why it's wrong here
Adding analysts addresses capacity, not the gap where a triggered alert sat unactioned during concurrent incidents. The failure is alert routing and escalation, not headcount. Extra staff would be the right answer if sustained volume consistently exceeded the team's handling capacity across normal operations.
- ✗
Increase the threshold to reduce false positives.
Why it's wrong here
Raising thresholds suppresses genuine detections alongside false positives, so the ignored alert may never fire again. Threshold tuning suits environments drowning in noisy benign alerts. This scenario's failure was a real alert going unhandled during concurrent incident work, which threshold changes cannot address.
- ✓
Configure automatic escalation to a secondary response team if the alert is not acknowledged within a set time.
Why this is correct
Automatic escalation to a secondary response team when an alert goes unacknowledged within a defined window ensures coverage during concurrent incidents. This satisfies the need to close monitoring gaps caused by the primary team being occupied elsewhere.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.