CISM · Question #244
Which of the following is the MOST effective way to detect information security incidents?
The correct answer is C. Threshold settings on key risk indicators (KRIs). Threshold settings on Key Risk Indicators (KRIs) are the most effective detection mechanism because they trigger automated alerts the moment a metric crosses a predefined acceptable limit. Unlike periodic log reviews (B), which are retrospective and time-delayed, or real-time mon
Question
Which of the following is the MOST effective way to detect information security incidents?
Options
- AImplementation of regular security awareness programs
- BPeriodic analysis of security event log records
- CThreshold settings on key risk indicators (KRIs)
- DReal-time monitoring of network activity
How the community answered
(38 responses)- A5% (2)
- B13% (5)
- C71% (27)
- D11% (4)
Explanation
Threshold settings on Key Risk Indicators (KRIs) are the most effective detection mechanism because they trigger automated alerts the moment a metric crosses a predefined acceptable limit. Unlike periodic log reviews (B), which are retrospective and time-delayed, or real-time monitoring (D), which is passive and requires constant human attention, KRI thresholds create proactive, systematic, and automated detection that fires as soon as risk levels become abnormal. Security awareness programs (A) are preventive, not detective, controls.
Topics
Community Discussion
No community discussion yet for this question.