nerdexam
Isaca

CGEIT · Question #639

Forensic analysis revealed an attempted breach of a personnel database containing sensitive data. A subsequent investigation found that no one within the enterprise was aware of the breach attempt, ev

The correct answer is D. The implementation of an intrusion detection and reporting process. To prevent future undetected breaches, IT governance must require the implementation of an intrusion detection and reporting process, ensuring that unauthorized access attempts are immediately identified and escalated. This process closes the gap between log entries and actionabl

Submitted by khalil_dz· Apr 18, 2026Governance of Enterprise IT

Question

Forensic analysis revealed an attempted breach of a personnel database containing sensitive data. A subsequent investigation found that no one within the enterprise was aware of the breach attempt, even though logs recorded the unauthorized access actions. To prevent a similar situation in the future, what is MOST important for IT governance to require?

Options

  • APeriodic analyses of logs and databases for unusual activity
  • BA review of the information security and risk management frameworks
  • CThe creation of a comprehensive data management and storage policy
  • DThe implementation of an intrusion detection and reporting process

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    14% (6)
  • C
    7% (3)
  • D
    74% (32)

Why each option

To prevent future undetected breaches, IT governance must require the implementation of an intrusion detection and reporting process, ensuring that unauthorized access attempts are immediately identified and escalated. This process closes the gap between log entries and actionable alerts.

APeriodic analyses of logs and databases for unusual activity

Periodic analyses are reactive and might still miss real-time threats; the problem was the lack of *awareness* at the time of the event, not just the lack of analysis.

BA review of the information security and risk management frameworks

Reviewing frameworks is a high-level governance activity; while important, it doesn't directly address the operational gap of real-time detection and notification of security incidents.

CThe creation of a comprehensive data management and storage policy

A data management policy defines how data is handled but doesn't, by itself, create the active monitoring and alerting mechanisms needed to detect and report unauthorized access attempts.

DThe implementation of an intrusion detection and reporting processCorrect

The core issue was that unauthorized access occurred and was logged, but no one was aware. An intrusion detection system (IDS) specifically monitors network or system activities for malicious activity or policy violations and generates alerts. Coupling this with a robust reporting process ensures that detected events are promptly escalated to responsible personnel for investigation and response, making the organization aware of breach attempts in near real-time.

Concept tested: Intrusion detection and incident reporting

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/detection-response

Topics

#Information Security#Incident Management#IT Governance#Intrusion Detection

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice