nerdexam
Isaca

CISA · Question #310

Which of the following is the BEST way to determine the adequacy of controls for detecting inappropriate network activity in an organization?

The correct answer is A. Reviewing SIEM reports of suspicious events in a timely manner. Reviewing SIEM (Security Information and Event Management) reports of suspicious events in a timely manner is the best way to determine control adequacy because a SIEM aggregates and correlates logs across the entire network, providing comprehensive visibility into anomalous acti

Submitted by lukas.cz· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the BEST way to determine the adequacy of controls for detecting inappropriate network activity in an organization?

Options

  • AReviewing SIEM reports of suspicious events in a timely manner
  • BReviewing business application logs on a regular basis
  • CTroubleshooting connectivity issues routinely
  • DInstalling a packet filtering firewall to block malicious traffic

How the community answered

(51 responses)
  • A
    82% (42)
  • B
    6% (3)
  • C
    10% (5)
  • D
    2% (1)

Explanation

Reviewing SIEM (Security Information and Event Management) reports of suspicious events in a timely manner is the best way to determine control adequacy because a SIEM aggregates and correlates logs across the entire network, providing comprehensive visibility into anomalous activity - and the "timely manner" component ensures threats are detected and responded to before significant damage occurs.

Why the distractors are wrong:

  • B - Business application logs are too narrow in scope; they miss network-layer activity like port scans, lateral movement, or unauthorized access attempts between systems.
  • C - Troubleshooting connectivity issues is reactive and ad hoc, not a systematic control for detecting inappropriate activity.
  • D - A packet filtering firewall is a preventive control, not a detective control; installing it doesn't tell you whether your detection capabilities are adequate.

Memory tip: The question asks about detecting and determining adequacy - both point to monitoring and review. When you see "detect + adequacy," think SIEM (the single pane of glass for security monitoring). Firewalls block, logs record, but only a SIEM with timely review tells you if your controls are working.

Topics

#SIEM#Network Security Monitoring#Detective Controls#Control Adequacy

Community Discussion

No community discussion yet for this question.

Full CISA Practice