Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security analyst is reviewing the organization's SIEM and notices that the daily log volume dropped by 60 percent overnight, but no maintenance window was scheduled. The analyst must determine whether this is a genuine reduction in activity or a monitoring failure. Which action should the analyst take FIRST to validate the health of the monitoring capability?

⚠ Common exam trap

The trap here is assuming a drop in log volume means the environment became quieter, rather than suspecting that a log source stopped reporting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a log-source inventory reconciliation against the SIEM's expected asset list and verify each critical source is actively sending events.

A sharp, unexplained decrease in collected logs points to a monitoring failure rather than a quiet network. The fastest way to confirm this is to compare the SIEM's expected log sources with those actually reporting. Identifying silent sources restores visibility and prevents the organization from operating blind while believing it is fully monitored.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Perform a log-source inventory reconciliation against the SIEM's expected asset list and verify each critical source is actively sending events.

    Why this is correct

    A sudden drop in log volume usually indicates one or more sources stopped forwarding. Reconciling the expected source inventory against what the SIEM currently receives identifies silent sources, such as a failed collector or broken agent, before assuming the environment is quiet. This directly validates monitoring coverage and restores visibility.

  • ✗

    Increase the severity threshold for correlation rules so that only high-priority alerts are generated while the volume anomaly is investigated.

    Why it's wrong here

    Raising severity thresholds reduces alert noise but does nothing to determine why log ingestion fell. It can also hide real attacks during a period when visibility is already degraded. The scenario asks for validation of monitoring health, not tuning of alert output, so this action misdirects effort and prolongs the blind spot.

  • ✗

    Run a full vulnerability scan against the entire environment to confirm whether any systems have stopped responding.

    Why it's wrong here

    A vulnerability scan tests hosts for known weaknesses; it does not verify that those hosts are forwarding logs to the SIEM. A host can be fully responsive to scanning yet have a broken logging agent. This action consumes significant time and does not address the suspected monitoring failure.

  • ✗

    Review the SIEM's storage utilization and archive older logs to free capacity for incoming events.

    Why it's wrong here

    Storage pressure could affect retention, but a 60 percent overnight drop in ingestion is not explained by disk usage alone, and archiving older data does not restore missing sources. This is premature remediation without diagnosis and may destroy evidence needed to reconstruct the timeline of the monitoring gap.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.