hardMultiple Choice
CAS-004 Practice Question: A large enterprise has deployed a security…
A large enterprise has deployed a security information and event management (SIEM) system that ingests logs from all critical servers, network devices, and endpoints. The SIEM is configured to correlate events and generate alerts for suspicious activities. Recently, the SOC team has been overwhelmed by a high volume of false positive alerts, particularly from the web server farm. The false positives are mainly triggered by legitimate web crawling and scanning activities from partners and internal tools. The SOC manager wants to reduce false positives without missing real threats. As the security architect, you are asked to recommend a solution. Which of the following is the BEST course of action?
⚠ Common exam trap
Watch out — candidates often confuse reducing log volume (Option B) with reducing false positives, or assume that global tuning (Options A and C) is safer than targeted allowlisting, when in fact allowlisting preserves detection fidelity for unknown threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create allowlists for known legitimate sources (e.g., partner IP ranges, internal scanners) in the SIEM correlation rules.
Creating allowlists for known legitimate sources (e.g., partner IP ranges, internal scanners) in the SIEM correlation rules directly addresses the root cause: false positives from trusted entities. This approach preserves detection sensitivity for unknown or malicious sources while suppressing alerts from pre-vetted IPs, reducing alert fatigue without compromising security coverage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the event threshold for web server alerts to reduce sensitivity.
Why it's wrong here
Raising the threshold suppresses alerts once counts fall below the limit, so genuine threats generating fewer events than the new threshold pass silently. Threshold tuning is tempting for noisy detections, but it reduces sensitivity across all web activity rather than excluding the known legitimate crawler and scanner sources.
- ✗
Disable logging of successful requests on the web servers to reduce log volume.
Why it's wrong here
Disabling successful-request logging removes the baseline records needed to distinguish legitimate crawling from malicious scanning, creating blind spots. It is tempting because it directly cuts log volume from the web farm, but the goal is reducing false positives while retaining detection, which requires filtering known-good sources, not discarding success data.
- ✗
Tune the SIEM to use more aggressive deduplication and aggregation globally.
Why it's wrong here
Global deduplication and aggregation collapse repeated events into single alerts, which hides distinct malicious activity sharing signatures with benign traffic. It is tempting because it lowers alert volume everywhere, but the requirement is to exclude known legitimate crawler and scanner sources specifically, not to merge unrelated events enterprise-wide.
- ✓
Create allowlists for known legitimate sources (e.g., partner IP ranges, internal scanners) in the SIEM correlation rules.
Why this is correct
Allowlisting known partner IP ranges and internal scanners suppresses alerts generated by legitimate crawling and scanning, cutting false positives without disabling detection logic for genuine threats. It targets the specific noise source rather than broadly weakening correlation rules.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.