Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

In a case review, a firm's intrusion detection system generated alerts on unusual outbound data transfers for several weeks, but no analyst investigated them and the exfiltration continued. Which conclusion is MOST appropriate?

The detective control existed but was ineffective due to poor monitoring and response. The system produced alerts, yet nobody investigated them, so exfiltration continued. The weakness lies in triage, staffing and escalation processes rather than in an absence of detection technology.

  1. AThe detective control existed but failed because of inadequate monitoring and response processesCorrect
  2. BThe preventive controls were too strict and blocked legitimate traffic
  3. CThe firm lacked any detective controls
  4. DThe incident is purely an inherent risk issue unrelated to controls

Explanation

Alerts were generated, so a detective control was present. The failure was in human follow-up and response procedures, such as staffing, triage and escalation. Saying no detective control existed contradicts the facts.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions