Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address to a domain controller at 3:00 AM. The user associated with the account is on vacation. Which classification best describes this alert?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

True positive

The alert is triggered by a real failed login attempt from an internal IP, but the user is on vacation, so it likely indicates a malicious attempt. Since it is a confirmed security incident, it is a true positive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    False positive

    Why it's wrong here

    A false positive occurs when a security control or SIEM rule incorrectly flags legitimate, benign network traffic or system activity as malicious. In this scenario, because the alert triggered on actual suspicious behavior that warrants investigation, classifying it as a false positive is incorrect. Analysts must continuously tune rules to minimize these occurrences to prevent alert fatigue.

  • ✗

    False negative

    Why it's wrong here

    A false negative represents a critical security failure where malicious activity bypasses detection mechanisms entirely, resulting in no alert being generated. Because the SIEM successfully detected the event and generated an alert for the analyst to review, this scenario cannot be classified as a false negative. Security teams often perform threat hunting to uncover these undetected gaps.

  • ✗

    True negative

    Why it's wrong here

    A true negative is a state where benign, authorized activity correctly flows through the network without triggering any security alerts. Since an alert was actively generated by the SIEM in this scenario, the system did not remain silent, making the concept of a true negative completely inapplicable to this active alert investigation.

  • ✓

    True positive

    Why this is correct

    A true positive occurs when a security monitoring tool correctly identifies and alerts on actual malicious or unauthorized activity. In this case, the SIEM alert successfully flagged a genuine security event that requires analyst triage and incident response. Validating true positives is a fundamental step in the incident handling lifecycle before escalating to containment.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.