Greatest concern for SIEM implementation review

SIEM Implementation
Answer Correct answer: B — Network monitoring events must be aggregated into the SIEM to ensure comprehensive threat visibility.

Which of the following should be the GREATEST concern for an IS auditor reviewing the implementation of a security information and event management (SIEM) system?

  1. SIEM rule tuning is only reviewed annually.
  2. Network monitoring events are not aggregated into the SIEM. Correct Answer
  3. Only the last seven days of logs from the SIEM are maintained for review.
  4. Security operations center (SOC) staff have not been fully trained on how to use the SIEM.

Community Votes

B
83%
D
17%

83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the principle that data availability is a prerequisite for analysis, often tripping up those who prioritize human training over fundamental data integrity.

When reviewing a SIEM implementation, the absence of critical data sources like network monitoring events is the primary concern identified by the community. Without comprehensive log aggregation, the system cannot effectively detect security threats.

Choosing D (lack of staff training) is a common mistake, as candidates often underestimate that missing data sources render the tool useless regardless of operator skill.

Community Discussion (4 comments)

a84n 👍 1 Selected: D
Answer D D. Security operations center (SOC) staff have not been fully trained on how to use the SIEM. Without proper training, SOC staff may not be able to effectively utilize the SIEM to detect and respond to security incidents.
marc4354345 👍 3 Selected: B
Network monitoring events are an important source. Even well trained personnel cannot compensate for missing data.
Sibsankar 👍 1
If personnel are proficient in using the SIEM, they can still utilize it effectively for threat detection and incident response. However, untrained personnel significantly hinder the SIEM's potential, posing a more substantial security risk. So , the answer is D
Rachy 👍 2 Selected: B
B. Non inclusive of network monitoring events

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is correct because a SIEM's effectiveness depends entirely on the breadth and depth of data ingested. If network monitoring events are excluded, the system has a significant blind spot, making it impossible to detect network-based intrusions or anomalies. As noted in comments, even skilled personnel cannot analyze data that does not exist within the system.

Why the Other Options Are Wrong

Option D is incorrect because while training is important, it is a process issue that can be remedied over time; missing data is a critical design flaw. Option A is less critical than B because some rule tuning is happening, whereas missing data means zero analysis for that vector. Option C is a retention issue which affects forensic depth, but unlike missing data, it does not prevent real-time detection.

Community Comment Notes

The community strongly supports B, emphasizing that well-trained staff cannot compensate for missing data sources (Comment 1). While a minority argued for D based on human error risks, the consensus maintains that data integrity and aggregation are foundational requirements for a SIEM.

Exam Strategy

Prioritize technical availability over human factors when evaluating tool effectiveness. Always remember that you cannot analyze or protect against what you cannot see or log.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide