SY0-701 Security Operations • 100 Questions
100 SY0-701 Security Operations practice questions with answers and explanations. Free, no signup.
A security operations analyst is tuning a SIEM correlation rule designed to detect brute-force password attacks against domain user accounts. The current rule generates an alert when a single user account has more than 10 failed logon attempts within a 5-minute window. The SOC team is overwhelmed by thousands of alerts each day, the vast majority of which are triggered by legitimate users who accidentally mistype their passwords. Which of the following modifications to the rule would most effectively reduce false positives while still detecting actual brute-force attacks?
Choose an answer to begin — your selection is scored in the full session.
100 questions · instant feedback and full explanations after every question.