Which of the following is MOST likely to reduce the effectiveness of a SIEM system?
A.
Lack of multi-factor authentication (MFA) for system access
B.
Weakly encrypted log files
C.
Misconfiguration of alert thresholds
D.
Complex user interface
The Answer Is:
C
This question includes an explanation.
Explanation:
Misconfigured alert thresholds can lead to either false positives (alert fatigue) or missed critical events, undermining the purpose of the SIEM.
“SIEM effectiveness relies on appropriate configuration. Poor threshold settings can result in either overwhelming alerts or failure to detect real threats.”