Courseiva
Security MonitoringmediumMultiple ChoiceObjective-mapped

200-201 Security Monitoring Practice Question

A SIEM correlation rule is designed to detect a brute-force attack. The rule triggers when an event includes 10 or more failed logins from the same source IP within 1 minute. An analyst sees an alert for 12 failed logins from IP 10.0.0.1 in 2 minutes. Why did the rule not trigger?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The time window is too short; the rule requires 10 failures in 1 minute, but this occurred over 2 minutes

The rule requires 10+ failures in 1 minute. In 2 minutes, the rate is 6 per minute, which is below threshold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The source IP is not in the watch list

    Why it's wrong here

    Watch lists are not part of this rule.

  • The time window is too short; the rule requires 10 failures in 1 minute, but this occurred over 2 minutes

    Why this is correct

    The rule defines a 1-minute window, so 12 failures in 2 minutes averages 6/min.

  • The rule only counts successful logins

    Why it's wrong here

    It counts failed logins.

  • The alert severity is too low

    Why it's wrong here

    Severity doesn't affect triggering.

About these practice questions

This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.