CGEIT · Question #639
Forensic analysis revealed an attempted breach of a personnel database containing sensitive data. A subsequent investigation found that no one within the enterprise was aware of the breach attempt, ev
The correct answer is D. The implementation of an intrusion detection and reporting process. To prevent future undetected breaches, IT governance must require the implementation of an intrusion detection and reporting process, ensuring that unauthorized access attempts are immediately identified and escalated. This process closes the gap between log entries and actionabl
Question
Forensic analysis revealed an attempted breach of a personnel database containing sensitive data. A subsequent investigation found that no one within the enterprise was aware of the breach attempt, even though logs recorded the unauthorized access actions. To prevent a similar situation in the future, what is MOST important for IT governance to require?
Options
- APeriodic analyses of logs and databases for unusual activity
- BA review of the information security and risk management frameworks
- CThe creation of a comprehensive data management and storage policy
- DThe implementation of an intrusion detection and reporting process
How the community answered
(43 responses)- A5% (2)
- B14% (6)
- C7% (3)
- D74% (32)
Why each option
To prevent future undetected breaches, IT governance must require the implementation of an intrusion detection and reporting process, ensuring that unauthorized access attempts are immediately identified and escalated. This process closes the gap between log entries and actionable alerts.
Periodic analyses are reactive and might still miss real-time threats; the problem was the lack of *awareness* at the time of the event, not just the lack of analysis.
Reviewing frameworks is a high-level governance activity; while important, it doesn't directly address the operational gap of real-time detection and notification of security incidents.
A data management policy defines how data is handled but doesn't, by itself, create the active monitoring and alerting mechanisms needed to detect and report unauthorized access attempts.
The core issue was that unauthorized access occurred and was logged, but no one was aware. An intrusion detection system (IDS) specifically monitors network or system activities for malicious activity or policy violations and generates alerts. Coupling this with a robust reporting process ensures that detected events are promptly escalated to responsible personnel for investigation and response, making the organization aware of breach attempts in near real-time.
Concept tested: Intrusion detection and incident reporting
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/detection-response
Topics
Community Discussion
No community discussion yet for this question.