Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A security analyst notices that the SIEM is…

A security analyst notices that the SIEM is generating an overwhelming number of low-priority alerts from a single application server. The server is critical to operations. What is the BEST approach to reduce noise without compromising security?

⚠ Common exam trap

It's easy for candidates to confuse 'reducing noise' with 'reducing monitoring,' leading them to choose threshold increases or outright exclusion, when the correct approach is to surgically filter known benign events while maintaining full detection coverage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a suppression rule for known benign patterns.

Suppression rules allow the SIEM to filter out known benign patterns (e.g., routine service checks or scheduled scans) while still capturing genuine threats. This reduces alert fatigue without disabling monitoring for the critical server, preserving visibility into anomalous or malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increase the severity threshold for that server's alerts.

    Why it's wrong here

    Increasing the severity threshold for a server's alerts globally elevates the minimum severity required for an event to trigger an alert from that specific source. While this might reduce the volume of low-priority notifications, it carries a significant risk of masking legitimate security incidents, including critical compromises, if their individual severity falls below the newly configured threshold. This approach lacks the necessary granularity to differentiate between benign noise and actual threats, potentially leading to a severe reduction in overall security posture by ignoring important indicators of compromise.

  • Disable all alerts from that server.

    Why it's wrong here

    Disabling all alerts from a specific server completely eliminates any real-time security visibility into its operational activities and potential threats. This action creates a significant blind spot within the security monitoring infrastructure, making it impossible to detect malicious behavior, policy violations, or system compromises originating from or targeting that server. Such a drastic measure severely degrades the organization's overall security posture and fundamentally violates the principle of continuous monitoring for critical assets.

  • Create a suppression rule for known benign patterns.

    Why this is correct

    Implementing a suppression rule specifically targets and filters out alerts generated by known, legitimate, and non-malicious system behaviors or application activities that are frequently observed. This method intelligently reduces alert fatigue by eliminating noise without compromising visibility into actual threats, as it allows all other, potentially malicious, activity to continue generating alerts. It optimizes SIEM effectiveness by focusing analyst attention on truly anomalous or suspicious events, improving incident response efficiency.

  • Exclude the server from SIEM monitoring.

    Why it's wrong here

    Excluding a server from SIEM monitoring entirely removes its logs and event data from the security information and event management system's analysis pipeline. This action renders the server completely unmonitored for security purposes, leaving it highly vulnerable to undetected attacks, insider threats, and compliance violations. It creates a critical and unacceptable gap in the organization's defensive capabilities, as no security intelligence would be gathered, correlated, or analyzed for that specific asset.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.