nerdexam
Isaca

CISM · Question #391

Which of the following is the PRIMARY reason to review the firewall logs when an external network-based attack is reported by the intrusion detection system (IDS)?

The correct answer is D. To validate the incident. When an IDS raises an alert for an external attack, the immediate priority is to determine whether it is a true positive or a false positive. Reviewing firewall logs provides an independent, corroborating data source to confirm whether the suspicious traffic actually traversed…

Submitted by viktor_hu· Apr 18, 2026Information Security Incident Management

Question

Which of the following is the PRIMARY reason to review the firewall logs when an external network-based attack is reported by the intrusion detection system (IDS)?

Options

  • ATo validate the payload signature
  • BTo devise the incident response strategy
  • CTo review network configurations
  • DTo validate the incident

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    10% (2)
  • D
    80% (16)

Explanation

When an IDS raises an alert for an external attack, the immediate priority is to determine whether it is a true positive or a false positive. Reviewing firewall logs provides an independent, corroborating data source to confirm whether the suspicious traffic actually traversed the network boundary, validating the incident before resources are committed to a full response. Validating the payload signature (A) is an IDS/IPS function and not the primary reason to consult firewall logs. Devising an incident response strategy (B) happens after the incident is confirmed. Reviewing network configurations (C) is a separate administrative activity unrelated to the immediate goal of confirming whether an attack occurred.

Topics

#Incident Response#Intrusion Detection System (IDS)#Firewall Logs#Incident Validation

Community Discussion

No community discussion yet for this question.

Full CISM Practice