Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
A recent security audit is reporting several unsuccessful login attempts being repeated at specific times during the day on an Internet facing authentication server. No alerts have been generated by the security information and event management (SIEM) system. What PRIMARY action should be taken to improve SIEM performance?
Correct Answer: D
If no alerts are being generated despite several unsuccessful login attempts at specific times, it suggests that the SIEM system's alarm thresholds may not be set appropriately. Reviewing and adjusting the thresholds to ensure that such patterns of activity are detected and alerted upon is a primary step in improving SIEM performance. Other actions, such as enhancing logging detail or auditing firewall logs, are useful but secondary to ensuring that the SIEM is configured to detect and respond to potential security incidents effectively.