Courseiva
mediumDrag & DropObjective-mapped

CAS-004 Practice Question: Drag and drop the steps to set up a SIEM alert…

Drag and drop the steps to set up a SIEM alert for a failed login threshold into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Identify log source, then create rule, then set threshold, then configure response, then enable and test

SIEM rule creation: identify log source, create rule, set threshold, configure response, then enable and test.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identify log source, then create rule, then set threshold, then configure response, then enable and test

    Why this is correct

    This is the correct order because you must first identify the log source to know what events to monitor, then create the rule to define the condition, set the threshold to specify the number of failures, configure the response actions (e.g., email alert), and finally enable and test the rule to ensure it works.

  • Set threshold, then create rule, then identify log source, then configure response, then enable and test

    Why it's wrong here

    This is incorrect because you cannot set a threshold before knowing the log source and creating the rule; the threshold is part of the rule definition and depends on the log source.

  • Identify log source, then set threshold, then create rule, then configure response, then enable and test

    Why it's wrong here

    This is incorrect because the threshold should be set after the rule is created, not before; the rule defines the event to monitor and then the threshold specifies the count.

  • Create rule, then identify log source, then set threshold, then enable and test, then configure response

    Why it's wrong here

    This is incorrect because you need to identify the log source before creating a rule, and you must configure the response before enabling and testing; otherwise, the alert may trigger without any action.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.