CAS-003 · Question #686
A security analyst is reviewing weekly email reports and finds an average of 1.000 emails received daily from the internal security alert email address. Which of the following should be implemented?
The correct answer is B. Separation of duties for systems administrators. Receiving an average of 1,000 security alerts per day from an internal security alert address is an abnormally high volume originating from inside the organization. This pattern suggests that one or more system administrators may have excessive, unchecked privileges allowing…
Question
A security analyst is reviewing weekly email reports and finds an average of 1.000 emails received daily from the internal security alert email address. Which of the following should be implemented?
Options
- ATuning the networking monitoring service
- BSeparation of duties for systems administrators
- CMachine learning algorithms
- DDoS attack prevention
How the community answered
(24 responses)- A4% (1)
- B83% (20)
- C8% (2)
- D4% (1)
Explanation
Receiving an average of 1,000 security alerts per day from an internal security alert address is an abnormally high volume originating from inside the organization. This pattern suggests that one or more system administrators may have excessive, unchecked privileges allowing them to perform actions that continuously trigger alerts - whether intentionally or unintentionally. Implementing separation of duties ensures that no single administrator has enough access to perform all aspects of a sensitive operation alone, reducing the likelihood of insider-caused alert storms. Tuning network monitoring would apply if the alerts were from external/network anomalies. Machine learning and DoS prevention do not address the internal origin of the alerts.
Topics
Community Discussion
No community discussion yet for this question.