AAISM · Question #192
When evaluating a new AI tool for intrusion prevention, which is MOST important to ensure fit within the existing program architecture?
The correct answer is C. Confirm tool capabilities align with control objectives. Confirming that a tool's capabilities align with the organization's defined control objectives is the foundational evaluation step - it ensures the tool solves the right problem within the security program. All other features are only valuable if this alignment exists…
Question
When evaluating a new AI tool for intrusion prevention, which is MOST important to ensure fit within the existing program architecture?
Options
- AEnsure automated response orchestration
- BPrioritize real-time anomaly detection
- CConfirm tool capabilities align with control objectives
- DSelect a tool that integrates with the SIEM
How the community answered
(40 responses)- A8% (3)
- B15% (6)
- C73% (29)
- D5% (2)
Explanation
Confirming that a tool's capabilities align with the organization's defined control objectives is the foundational evaluation step - it ensures the tool solves the right problem within the security program. All other features are only valuable if this alignment exists. Automated response orchestration (A) and real-time anomaly detection (B) are desirable technical features but secondary to whether the tool meets the control objective. SIEM integration (D) is an important operational consideration but is still a technical integration concern subordinate to the question of whether the tool actually fulfills its intended security function.
Topics
Community Discussion
No community discussion yet for this question.