Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A financial services firm operates a Security Operations Center that ingests NetFlow records, firewall logs, and endpoint telemetry into a SIEM. An analyst wants to reduce alert fatigue while still surfacing high-fidelity detections. Which approach best supports this goal?

⚠ Common exam trap

The trap here is assuming that fewer alerts always means better monitoring, when the real goal is higher-fidelity alerts prioritized by risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tune correlation rules with asset context and threat intelligence, and implement risk-based alert scoring to prioritize detections

Alert fatigue is reduced by improving the quality and context of detections, not by removing or delaying them. Enriching correlation rules with asset criticality and threat intelligence, then scoring alerts by risk, lets analysts focus on events that matter to the business. This maintains coverage while cutting noise, which is the core objective of a mature monitoring program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tune correlation rules with asset context and threat intelligence, and implement risk-based alert scoring to prioritize detections

    Why this is correct

    Combining asset criticality, threat intelligence, and risk-based scoring lets the SIEM rank alerts by actual business risk rather than raw event volume. Rules can be tuned to suppress known-good activity, while enrichment highlights activity tied to critical systems or active threat campaigns. This preserves detection coverage and directs analyst attention to the alerts most likely to represent real incidents, directly reducing fatigue without weakening monitoring.

  • ✗

    Increase the severity rating of every rule so that analysts prioritize all alerts equally

    Why it's wrong here

    Raising every rule to the same severity destroys prioritization and makes alert fatigue worse, because analysts cannot distinguish critical events from routine noise. Effective triage depends on differentiated severity aligned to business impact. This change also ignores the need to tune rule logic or add contextual enrichment. It is the opposite of reducing fatigue while preserving high-fidelity detections.

  • ✗

    Route all alerts to a shared mailbox and require analysts to review them only during weekly meetings

    Why it's wrong here

    Batching alerts for weekly review delays detection and response, allowing attackers to persist and expand access. It also does nothing to improve alert quality; the same volume simply accumulates. Timely monitoring requires near-real-time triage, and high-fidelity detections must be acted on quickly. This approach undermines the purpose of the Security Operations Center rather than reducing fatigue constructively.

  • ✗

    Disable all correlation rules that generate more than ten alerts per day and rely solely on raw log review

    Why it's wrong here

    Disabling noisy rules outright removes detection coverage and shifts the burden to manual raw log review, which does not scale and will miss threats. The goal is to improve signal quality, not to eliminate detection logic. Correlation rules that fire often may still catch real activity, so they should be tuned with context rather than deleted. This approach increases risk while reducing analyst effectiveness.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.