Courseiva
mediumMultiple Choice

How Do You Reduce False Positives in a SIEM Correlation Rule for Failed Logins?

A security analyst notices repeated failed login attempts to a critical server from a single external IP address over the past 30 minutes. The SIEM has a correlation rule that triggers an alert when the threshold of 10 failed attempts in 5 minutes is exceeded. However, no alert was generated. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between event frequency over a long period versus event rate within a specific time window, trapping candidates who assume any repeated failed login attempts will trigger an alert regardless of the correlation rule's temporal constraints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The correlation rule uses a sliding window, and the failed attempts occurred over more than 5 minutes.

The SIEM correlation rule uses a sliding window that triggers an alert only when 10 failed attempts occur within a 5-minute window. Since the analyst observed repeated failed attempts over 30 minutes, the attempts are spread across multiple 5-minute windows, so no single window exceeds the threshold. This is a classic case where the event frequency is high overall but does not meet the rule's temporal aggregation criteria.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SIEM is not receiving logs from the authentication server.

    Why it's wrong here

    If the SIEM received no authentication logs, the correlation rule could never evaluate the failed attempts, so no alert fires regardless of threshold. It is tempting because log ingestion failures are common, but the scenario states the analyst observes the attempts, implying logs exist and the rule logic itself is the gap.

  • ✓

    The correlation rule uses a sliding window, and the failed attempts occurred over more than 5 minutes.

    Why this is correct

    A sliding window evaluates events only within the trailing five minutes, so ten failures spread across a longer period never accumulate to the threshold at any single evaluation point. The rule therefore stays silent despite the sustained attack.

  • ✗

    The analyst is monitoring the wrong log source.

    Why it's wrong here

    Monitoring the wrong log source would mean the analyst sees unrelated events rather than the authentication failures, yet the stem describes observing those exact attempts. It is tempting because source misconfiguration causes missed alerts, but the correct source is evidently feeding the analyst's view, so the correlation rule's threshold or grouping is the fault.

  • ✗

    The SIEM correlation rule requires a minimum of 15 failed attempts.

    Why it's wrong here

    A rule requiring 15 failed attempts in 5 minutes would not trigger on the observed pattern if fewer than 15 occurred within each window, explaining the silence. It is tempting because threshold misconfiguration is a frequent cause, but the stem specifies the rule triggers at 10, so this contradicts the stated configuration.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.