Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 657 discussion

Actual exam question from Isaca's CISA
Question #: 657
Topic #: 1
[All CISA Questions]

Following the implementation of a data loss prevention (DLP) tool, administrators have been overwhelmed with a high number of false positives. Which of the following is the BEST way to address this issue?

  • A. Enable monitoring-only mode to permit further tuning of the solution.
  • B. Educate staff about the risks of sharing sensitive information outside the organization.
  • C. Amend policy rules to match approved and unapproved business information pathways.
  • D. Ensure the latest signature files are present and configure regular updates.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
saado9
Highly Voted 1 year, 6 months ago
A. Enable monitoring-only mode to permit further tuning of the solution.
upvoted 5 times
...
Swallows
Most Recent 4 months ago
Selected Answer: A
Proper configuration and rule definition are important for DLP tools to function accurately. We recommend using monitor-only mode to minimize false positives while evaluating your actual operational situation.
upvoted 1 times
...
KAP2HURUF
5 months ago
Selected Answer: C
A. Enable monitoring-only mode to permit further tuning of the solution. Here’s a concise rationale for why this option is the most effective: Enabling monitoring-only mode allows the DLP tool to continue monitoring and generating alerts without taking any enforcement actions (such as blocking or quarantining files). This approach temporarily reduces the impact of false positives on administrators, enabling them to analyze and understand the alerts more comprehensively. Further tuning of the DLP solution based on the data gathered during the monitoring-only period helps in identifying patterns and refining policies to reduce false positives while maintaining effective detection of actual data breaches or policy violations.
upvoted 1 times
...
JONESKA
1 year, 4 months ago
Should be C. Enabling monitoring-only mode (option A) may provide insights for further tuning, but it does not directly address the issue itself. Educating staff about risks (option B) is important for overall security awareness, but it may not immediately reduce false positives. Ensuring the latest signature files and regular updates (option D) is essential for maintaining the effectiveness of the DLP tool, but it may not directly address the issue of false positives.
upvoted 4 times
...
ItsBananass
1 year, 4 months ago
from the internet: To address this issue, administrators should enable monitoring-only mode in order to fine-tune the solution. This will allow them to monitor system activity without immediately taking action on any alerts that are triggered by suspicious activity.
upvoted 1 times
...
Pakawat
1 year, 5 months ago
Why not C ?
upvoted 2 times
...
BabaP
1 year, 6 months ago
Selected Answer: A
A is the answer
upvoted 2 times
...
kertyce
1 year, 9 months ago
it shoud be C
upvoted 2 times
...
gomboragchaa
1 year, 11 months ago
Why signature files need for DLP solution? I think D isn't correct answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...