Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from a known internal IP address to a file server. The user authenticated successfully on the next attempt. Which classification best describes this alert?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False positive

The alert is a false positive because a single failed login followed by success is normal user behavior and not indicative of malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    True negative

    Why it's wrong here

    A true negative by definition means the SIEM correctly stayed silent because no suspicious condition was present; that classification cannot apply here since an alert was actually generated and triggered analyst review, so this scenario cannot be a true negative regardless of how benign the underlying activity turned out to be.

  • ✗

    True positive

    Why it's wrong here

    A true positive requires the alert to correctly reflect a genuine malicious or unauthorized event; a single failed login from a known internal IP followed immediately by successful authentication on the next attempt is consistent with an ordinary mistyped password rather than an actual account compromise or brute-force attempt, so labeling this a true positive would misrepresent normal user behavior as a real threat.

  • ✗

    False negative

    Why it's wrong here

    A false negative describes the opposite failure mode, where a genuine threat exists but the detection system stays silent and produces no alert at all; here the SIEM did fire an alert, so the classification cannot be a false negative regardless of whether the underlying activity was later judged benign.

  • ✓

    False positive

    Why this is correct

    This is a false positive because the alert fired on a single failed login from a known, trusted internal IP that was immediately followed by successful authentication, a pattern far more consistent with a routine typo than malicious activity; the detection rule's threshold for triggering on just one failed attempt is overly sensitive and should likely be tuned to require multiple failures before alerting.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.