712-50 Question 196
Single answerDomain 3: Information Security Controls, Security Program Management & Operations (12%)A newly appointed CISO is reviewing the organization's security operations after a ransomware incident disrupted several regional business units. The post-incident review found that endpoint detection alerts were generated, but the security team did not escalate them because analysts were overwhelmed by thousands of low-value events. The board has asked the CISO to improve detection and response without significantly increasing headcount in the next two quarters. Which action should the CISO prioritize FIRST to most effectively improve security operations in this situation?
- A
Implement a risk-based alert triage and tuning program to reduce false positives, refine use cases, and establish escalation thresholds for high-impact events
- B
Purchase an additional security monitoring platform so alerts from multiple tools can be viewed in a single dashboard
- C
Mandate that all medium- and high-severity alerts be investigated manually by analysts until incident volume decreases
- D
Outsource all incident response activities to a third-party provider to ensure 24/7 coverage
Show answer and explanation
Correct answer: A
Explanation
The best first step is to improve the effectiveness of existing security operations by tuning detections, establishing risk-based prioritization, and defining clear escalation criteria tied to business impact. This is consistent with security operations best practices found in sources such as NIST SP 800-61 Rev. 2 for incident handling and NIST SP 800-137 for ongoing monitoring, both of which emphasize actionable monitoring, prioritization, and response processes. From a CCISO perspective, the CISO should focus on management actions that improve control effectiveness, operational efficiency, and alignment to enterprise risk. In this scenario, the lesson is that excessive alert volume without disciplined triage creates operational failure even when technical controls are present. Addressing people-process-technology balance is more effective than immediately buying new tools or expanding staffing.
- A. Correct.
Correct. The core problem is not the absence of alerts, but ineffective operationalization of detection due to alert fatigue and poor prioritization. A risk-based triage and tuning program addresses the root cause by improving signal-to-noise ratio, aligning escalation to business impact, and enabling analysts to focus on the most consequential events. In Domain 3, this reflects effective security operations management, control optimization, and use-case maturity rather than simply adding tools or labor.
- B. Incorrect.
Incorrect. Consolidated visibility can be useful, but adding another platform does not directly solve the immediate issue of low-quality alerts and overwhelmed analysts. If the existing detections are poorly tuned, a new dashboard may merely centralize noise rather than improve operational effectiveness. This option reflects a common misconception that tooling alone solves process and management deficiencies.
- C. Incorrect.
Incorrect. Requiring manual investigation of all medium- and high-severity alerts may appear prudent after a ransomware incident, but it is operationally unsustainable when staff are already overloaded and headcount cannot increase. Without better tuning and prioritization, this approach can worsen burnout, increase response delays, and reduce the team's ability to focus on genuinely critical incidents.
- D. Incorrect.
Incorrect. A third-party provider may improve coverage, but fully outsourcing incident response is not the best first action based on the scenario. The organization's immediate issue is alert quality and escalation discipline, which must be addressed regardless of whether operations are internal, co-managed, or outsourced. Transferring the function without fixing detection logic and triage processes can simply move inefficiency to another team at higher cost.