CS0-003 Security Operations Practice Question
A security analyst is reviewing a SIEM alert indicating a high number of failed authentication attempts from a single IP address against multiple user accounts. The analyst checks the logs and finds the IP belongs to a known vulnerability scanner used by the internal security team. How should the analyst classify this alert?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
False positive - authorized activity
The alert is triggered by authorized activity from a known internal scanner, so it is a false positive. The SIEM rule should be tuned to exclude this scanner or reduce its severity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
True positive - unauthorized access attempt
Why it's wrong here
This classification is incorrect because the activity originates from an approved internal vulnerability scanner rather than an external threat actor or unauthorized user. A true positive requires the flagged event to represent actual malicious or unauthorized behavior. Since the scanning tool is performing scheduled, permitted security assessments, it does not constitute an unauthorized access attempt.
- ✓
False positive - authorized activity
Why this is correct
This is the correct classification because the SIEM generated an alert for behavior that, while anomalous or aggressive in appearance, is actually benign and pre-authorized. Vulnerability scanners frequently trigger brute-force or account-harvesting alerts during routine credentialed checks. Labeling this as a false positive allows analysts to tune the SIEM rules to exclude the scanner's IP address from future alerts.
- ✗
True positive - lateral movement
Why it's wrong here
Lateral movement involves an attacker compromising one host and using it as a pivot point to compromise adjacent systems. In this scenario, a single authorized vulnerability scanner is systematically probing multiple accounts or assets from a centralized, known administrative source. There is no evidence of cascading compromises or unauthorized pivoting across the network.
- ✗
False negative - missed detection
Why it's wrong here
This choice is incorrect because a false negative occurs when malicious activity takes place but the security controls fail to detect or alert on it. In this case, the SIEM successfully triggered an alert based on the scanner's noisy activity. Because an alert was generated and presented to the analyst, the event cannot be classified as a missed detection.
Go deeper
Related to this question
Learn chapter
Nessus Vulnerability Scanner
Key term
Vulnerability scanner
A vulnerability scanner is an automated tool that identifies security weaknesses in systems, networks, and applications by comparing their configurations and software versions against known vulnerability databases.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.