nerdexam
Isaca

CDPSE · Question #265

An organization that stores personal information is receiving an excessive number of alerts from its intrusion detection system (IDS), causing follow-through to become unfeasible. What should be…

The correct answer is B. Conduct a root cause analysis. Before taking any corrective action-whether reconfiguring rules, replacing the IDS, or initiating a privacy review-you must first understand WHY the alert volume is so high. A root cause analysis determines whether the flood is caused by misconfigured rules, a genuine attack…

Privacy Architecture

Question

An organization that stores personal information is receiving an excessive number of alerts from its intrusion detection system (IDS), causing follow-through to become unfeasible. What should be done FIRST?

Options

  • AImplement an IDS with artificial intelligence (AI) features.
  • BConduct a root cause analysis.
  • CPerform a privacy impact assessment (PIA).
  • DReconfigure IDS alert rules.

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    84% (42)
  • C
    10% (5)
  • D
    2% (1)

Explanation

Before taking any corrective action-whether reconfiguring rules, replacing the IDS, or initiating a privacy review-you must first understand WHY the alert volume is so high. A root cause analysis determines whether the flood is caused by misconfigured rules, a genuine attack, noisy network behavior, outdated signatures, or another underlying issue. Without this diagnosis, any fix (such as reconfiguring rules in option D) risks suppressing legitimate threats or solving the wrong problem entirely. Root cause analysis is always the first step when addressing a systemic operational issue.

Topics

#IDS#Alert Management#Root Cause Analysis#Operational Security

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice