A government contractor is required to comply with the Federal Information Security Management Act (FISMA). The security officer must implement a continuous monitoring program for all information systems. The contractor uses a mix of on-premises servers and cloud services. The contractor has a SIEM tool that collects logs from all systems. However, the SIEM generates a high number of alerts, many of which are false positives, overwhelming the security team. The team wants to improve the effectiveness of the monitoring program without increasing staff. Which of the following actions would MOST effectively address the issue?
Tuning correlation rules and building custom filters directly targets the false-positive volume that overwhelms the team, satisfying the constraint of improving monitoring effectiveness without adding staff. By refining detection logic against the contractor's actual baseline across on-premises and cloud sources, genuine FISMA-relevant events surface, restoring continuous monitoring capability.
Why this answer
Tuning SIEM correlation rules and creating custom filters directly addresses the root cause of false positives by refining detection logic to match the contractor's specific environment and threat profile. This reduces alert noise without discarding potentially valuable low-severity data or requiring additional staff. It aligns with FISMA continuous monitoring requirements by improving the signal-to-noise ratio, enabling the existing team to focus on genuine threats.
This is the most effective and sustainable solution because it enhances the tool's accuracy rather than just suppressing or adding resources.
Exam trap
SSCP often tests the misconception that simply suppressing alerts or adding staff solves alert fatigue, when the most effective solution is to refine the detection logic itself.
How to eliminate wrong answers
Option A is wrong because disabling all low-severity alerts can cause the team to miss early indicators of compromise or correlated events that, in aggregate, signify a real attack, and it does not address the underlying issue of false positives among higher-severity alerts. Option B is wrong because hiring additional analysts increases costs and does not improve the monitoring program's effectiveness; it merely adds manpower to handle the same volume of false positives, which is unsustainable and contrary to the goal of not increasing staff. Option C is wrong because increasing log collection frequency to every minute would generate even more data and likely more alerts, exacerbating the false positive problem and overwhelming the team further, without improving detection accuracy.