nerdexam
Isaca

CISM · Question #153

An intrusion prevention system (IPS) has reported a significant increase in the number of hacking attempts over the past month, though no systems have actually been compromised. Which of the…

The correct answer is C. Validate the events identified by the IPS. When an IPS reports a significant increase in hacking attempts without actual compromises, the information security manager should first validate the identified events. This step confirms the legitimacy of the alerts before taking further action.

Submitted by tunde_lagos· Apr 18, 2026Information Security Incident Management

Question

An intrusion prevention system (IPS) has reported a significant increase in the number of hacking attempts over the past month, though no systems have actually been compromised. Which of the following should the information security manager do FIRST?

Options

  • ATune the IPS to address false positives.
  • BReport the increase in hacking attempts to senior management.
  • CValidate the events identified by the IPS.
  • DUpdate security awareness training.

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    10% (5)
  • C
    71% (36)
  • D
    16% (8)

Why each option

When an IPS reports a significant increase in hacking attempts without actual compromises, the information security manager should first validate the identified events. This step confirms the legitimacy of the alerts before taking further action.

ATune the IPS to address false positives.

Tuning the IPS for false positives should only be done after validating the events, as prematurely tuning could lead to legitimate threats being missed.

BReport the increase in hacking attempts to senior management.

Reporting to senior management without first validating the events could lead to alarm based on inaccurate or incomplete information.

CValidate the events identified by the IPS.Correct

Before taking any other action, it is crucial to validate the events reported by the IPS to distinguish between actual legitimate attempts and potential false positives or misconfigurations. This validation ensures that resources are not wasted on non-existent threats and provides accurate data for subsequent decisions, such as tuning the IPS or reporting to management.

DUpdate security awareness training.

Updating security awareness training is a general security measure and not the immediate, direct response to an increase in IPS-reported hacking attempts that may or may not be legitimate.

Concept tested: Intrusion Prevention System (IPS) alert validation

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-for-endpoint/investigate-alerts-in-microsoft-defender-for-endpoint

Topics

#IPS#Incident Response#Alert Validation#Security Monitoring

Community Discussion

No community discussion yet for this question.

Full CISM Practice