CISM · Question #153
An intrusion prevention system (IPS) has reported a significant increase in the number of hacking attempts over the past month, though no systems have actually been compromised. Which of the…
The correct answer is C. Validate the events identified by the IPS. When an IPS reports a significant increase in hacking attempts without actual compromises, the information security manager should first validate the identified events. This step confirms the legitimacy of the alerts before taking further action.
Question
An intrusion prevention system (IPS) has reported a significant increase in the number of hacking attempts over the past month, though no systems have actually been compromised. Which of the following should the information security manager do FIRST?
Options
- ATune the IPS to address false positives.
- BReport the increase in hacking attempts to senior management.
- CValidate the events identified by the IPS.
- DUpdate security awareness training.
How the community answered
(51 responses)- A4% (2)
- B10% (5)
- C71% (36)
- D16% (8)
Why each option
When an IPS reports a significant increase in hacking attempts without actual compromises, the information security manager should first validate the identified events. This step confirms the legitimacy of the alerts before taking further action.
Tuning the IPS for false positives should only be done after validating the events, as prematurely tuning could lead to legitimate threats being missed.
Reporting to senior management without first validating the events could lead to alarm based on inaccurate or incomplete information.
Before taking any other action, it is crucial to validate the events reported by the IPS to distinguish between actual legitimate attempts and potential false positives or misconfigurations. This validation ensures that resources are not wasted on non-existent threats and provides accurate data for subsequent decisions, such as tuning the IPS or reporting to management.
Updating security awareness training is a general security measure and not the immediate, direct response to an increase in IPS-reported hacking attempts that may or may not be legitimate.
Concept tested: Intrusion Prevention System (IPS) alert validation
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-for-endpoint/investigate-alerts-in-microsoft-defender-for-endpoint
Topics
Community Discussion
No community discussion yet for this question.