mediumMultiple Choice
200-201 A company uses a SIEM with correlation rules Practice Question
A company uses a SIEM with correlation rules. They notice that a rule designed to detect brute-force attacks is not triggering even though failed logins are occurring. Which is the most likely cause?
⚠ Common exam trap
Cisco often tests the concept that a correlation rule's threshold is a direct control over its sensitivity, and candidates may mistakenly attribute the issue to data ingestion problems (like dropped logs or misconfigured time zones) rather than the rule's own configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The correlation rule threshold is set too high.
A SIEM correlation rule for brute-force attacks typically triggers when the number of failed login attempts from a single source exceeds a defined threshold within a specific time window. If the threshold is set too high, the rule will not fire even though failed logins are occurring, because the count never reaches the required value. This is the most direct and common cause for a correlation rule not triggering when expected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SIEM is receiving too many logs and dropping events.
Why it's wrong here
Log ingestion volume causing dropped events would suppress all rules, not specifically the brute-force correlation. Capacity tuning is the fix when overall event throughput saturates the SIEM, but here failed logins are evidently reaching the platform.
- ✓
The correlation rule threshold is set too high.
Why this is correct
Correlation rules fire only when the count of matching events within the rule's time window reaches the configured threshold. If that threshold is set too high, genuine brute-force activity generating failed logins never accumulates enough events to trigger an alert, explaining the absence of detections.
- ✗
The SIEM time zone is misconfigured.
Why it's wrong here
A misconfigured time zone shifts event timestamps, so correlation windows spanning the offset fail to group related failed logins. It is the right suspect when events arrive but fall outside the rule's threshold window, not when the rule never fires.
- ✗
The log source is not sending syslog data.
Why it's wrong here
Absent syslog data would mean no failed-login events arrive at all, contradicting the stem's statement that failed logins are occurring. It is the correct diagnosis when a source is entirely silent, not when events are present but uncorrelated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.