SIEM dashboards show repeated failed logons and impossible-travel alerts for municipal SSO, but the identity team never tunes or responds to them. What practice is missing?
Select an answer to reveal the explanation.
Short Explanation
Alarms that nobody answers might as well be wallpaper. Watch failed logons and impossible travel, tune them, and chase the weird stuff—that is authentication monitoring, not just collecting pretty charts.
Full Explanation
Authentication systems require ongoing monitoring for brute force, credential stuffing, impossible travel, and other misuse indicators, with triage and response playbooks. Ignoring SIEM signals wastes detection capability. Disabling SSO, weakening passwords, or prematurely deleting logs increase risk rather than improving detection quality.