ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During a security monitoring review, an organization discovers that its SOC ignores many notifications generated whenever a single server briefly exceeds its baseline for failed-login attempts. The security analyst must reconfigure notifications so the SOC receives an alert only when abnormal spikes persist across multiple evaluation periods, while still acting in near real time. Which configuration change BEST meets this requirement?
Disable near-real-time alerts and instead generate an hourly summary report of failed-login anomalies for manual SOC review.
Forward all failed-login events to the data lake for weekly audit analysis rather than sending live notifications.
Create a dynamic (statistical) threshold that triggers only after the baseline is breached in two consecutive evaluation periods and route the alert to the SOC's notification channel.
Keep the existing static threshold but change the notification to fire on every evaluation period regardless of duration.
Using a statistical, or dynamic, threshold allows the monitoring platform to compare current values against a rolling baseline rather than a fixed number. Requiring the condition to be met in two or more consecutive evaluation periods further reduces noise by suppressing alerts caused by transient spikes. This approach delivers a single, high-confidence alert to the SOC. A static threshold evaluated each period would still fire on brief anomalies, scheduled reports delay response, and simply archiving data provides no near-real-time notification.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a SOC (Security Operations Center)?
Open an interactive chat with Bash
What is the difference between a static and dynamic threshold?
Open an interactive chat with Bash
How does a rolling baseline work for monitoring anomalies?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .