CS0-003 Security Operations Practice Question
A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address to a domain controller at 3:00 AM. The user associated with the account is on vacation. Which classification best describes this alert?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
True positive
The alert is triggered by a real failed login attempt from an internal IP, but the user is on vacation, so it likely indicates a malicious attempt. Since it is a confirmed security incident, it is a true positive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
False positive
Why it's wrong here
A false positive occurs when a security control or SIEM rule incorrectly flags legitimate, benign network traffic or system activity as malicious. In this scenario, because the alert triggered on actual suspicious behavior that warrants investigation, classifying it as a false positive is incorrect. Analysts must continuously tune rules to minimize these occurrences to prevent alert fatigue.
- ✗
False negative
Why it's wrong here
A false negative represents a critical security failure where malicious activity bypasses detection mechanisms entirely, resulting in no alert being generated. Because the SIEM successfully detected the event and generated an alert for the analyst to review, this scenario cannot be classified as a false negative. Security teams often perform threat hunting to uncover these undetected gaps.
- ✗
True negative
Why it's wrong here
A true negative is a state where benign, authorized activity correctly flows through the network without triggering any security alerts. Since an alert was actively generated by the SIEM in this scenario, the system did not remain silent, making the concept of a true negative completely inapplicable to this active alert investigation.
- ✓
True positive
Why this is correct
A true positive occurs when a security monitoring tool correctly identifies and alerts on actual malicious or unauthorized activity. In this case, the SIEM alert successfully flagged a genuine security event that requires analyst triage and incident response. Validating true positives is a fundamental step in the incident handling lifecycle before escalating to containment.
Go deeper
Related to this question
Learn chapter
Lessons Learned and Post-Incident Activities
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.