Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 56 discussion

Actual exam question from Isaca's CISA
Question #: 56
Topic #: 1
[All CISA Questions]

Which of the following would be of GREATEST concern when reviewing an organization's security information and event management (SIEM) solution?

  • A. SIEM reporting is ad hoc.
  • B. SIEM reporting is customized.
  • C. SIEM configuration is reviewed annually.
  • D. The SIEM is decentralized.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Pumeza
1 week, 1 day ago
D. The SIEM is decentralized.
upvoted 1 times
...
a84n
6 months, 3 weeks ago
Selected Answer: D
Answer: D
upvoted 1 times
...
5b56aae
6 months, 4 weeks ago
Selected Answer: D
decentralization makes it inconsistent
upvoted 1 times
...
KAP2HURUF
10 months, 3 weeks ago
Selected Answer: B
Ad hoc review is not appropriate. SIEM without review or following up alert is useless.
upvoted 1 times
...
lsiau76
1 year, 2 months ago
Selected Answer: D
D. The SIEM is decentralized. The greatest concern when reviewing an organization's security information and event management (SIEM) solution would be if the SIEM is decentralized (Option D). A decentralized SIEM could lead to fragmented data, incomplete visibility, and difficulties in effectively monitoring and responding to security incidents. A centralized SIEM allows for consistent monitoring, analysis, and response across the organization's entire infrastructure, enhancing security and reducing blind spots.
upvoted 3 times
...
007Georgeo
1 year, 6 months ago
Selected Answer: D
D. The SIEM is decentralized
upvoted 2 times
...
Slurpistist
1 year, 7 months ago
D. The SIEM is decentralized. A decentralized SIEM can lead to gaps in monitoring and increased complexity in managing security events. This can result in a higher risk of security incidents going undetected or not being properly addressed. Therefore, a decentralized SIEM would be of greatest concern when reviewing an organization's security information and event management solution.
upvoted 2 times
...
Delta67
1 year, 8 months ago
I would choose D. SIEM should be not be decentralized, at least what I have seen it in my 20 years of experience
upvoted 4 times
...
survivalkit
1 year, 9 months ago
Selected Answer: A
An SIEM solution that lacks a standard, structured reporting process could lead to the missed detection of security events or the misinterpretation of events, which could have serious consequences for an organization's security posture. A structured reporting process, with clear definitions and criteria for security events, is critical for the effective use of a SIEM solution
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...