nerdexam
Isaca

CISM · Question #799

Which type of system is MOST effective for monitoring cyber incidents based on impact and tracking them until they are closed?

The correct answer is D. Security information and event management (SIEM). SIEM systems collect and analyze log data from across the organization, allowing for real-time monitoring, incident correlation, and end-to-end tracking of response activities - including severity classification and closure. "SIEM tools enable centralized management, prioritizati

Submitted by fernanda_arg· Apr 18, 2026Information Security Incident Management

Question

Which type of system is MOST effective for monitoring cyber incidents based on impact and tracking them until they are closed?

Options

  • AEndpoint detection and response (EDR)
  • BNetwork intrusion detection system (NIDS)
  • CExtended detection and response (XDR)
  • DSecurity information and event management (SIEM)

How the community answered

(27 responses)
  • A
    15% (4)
  • B
    4% (1)
  • C
    7% (2)
  • D
    74% (20)

Explanation

SIEM systems collect and analyze log data from across the organization, allowing for real-time monitoring, incident correlation, and end-to-end tracking of response activities - including severity classification and closure. "SIEM tools enable centralized management, prioritization, and documentation of incidents, making them essential for impact tracking and incident lifecycle management." While EDR and XDR help detect threats, SIEMs offer the full scope for impact-based tracking.

Topics

#SIEM#Incident Management#Security Monitoring#Security Systems

Community Discussion

No community discussion yet for this question.

Full CISM Practice