nerdexam
Isaca

CISM · Question #244

Which of the following is the MOST effective way to detect information security incidents?

The correct answer is C. Threshold settings on key risk indicators (KRIs). Threshold settings on Key Risk Indicators (KRIs) are the most effective detection mechanism because they trigger automated alerts the moment a metric crosses a predefined acceptable limit. Unlike periodic log reviews (B), which are retrospective and time-delayed, or real-time mon

Submitted by daniela_cl· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the MOST effective way to detect information security incidents?

Options

  • AImplementation of regular security awareness programs
  • BPeriodic analysis of security event log records
  • CThreshold settings on key risk indicators (KRIs)
  • DReal-time monitoring of network activity

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    13% (5)
  • C
    71% (27)
  • D
    11% (4)

Explanation

Threshold settings on Key Risk Indicators (KRIs) are the most effective detection mechanism because they trigger automated alerts the moment a metric crosses a predefined acceptable limit. Unlike periodic log reviews (B), which are retrospective and time-delayed, or real-time monitoring (D), which is passive and requires constant human attention, KRI thresholds create proactive, systematic, and automated detection that fires as soon as risk levels become abnormal. Security awareness programs (A) are preventive, not detective, controls.

Topics

#Incident Detection#Key Risk Indicators (KRIs)#Risk Monitoring#Security Monitoring

Community Discussion

No community discussion yet for this question.

Full CISM Practice