Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is reviewing SIEM alerts and notices a high volume of alerts for a specific event ID that has been determined to be benign. Which action should the analyst take to reduce noise?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a suppression rule for that event ID

True positive alerts are genuine threats; false positives are benign. Tuning the SIEM to suppress known false positives reduces alert fatigue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the severity of the alert

    Why it's wrong here

    Elevating the severity of an alert merely escalates its priority within the SIEM dashboard or ticketing system. It does nothing to filter out or reduce the overall volume of these false positive events, which will continue to cause alert fatigue for the security operations center (SOC) team.

  • ✗

    Reclassify the alert as a true positive

    Why it's wrong here

    Marking these benign events as true positives is inaccurate and will skew historical metrics, leading to flawed reporting and wasted incident response resources. Furthermore, this action does not stop the SIEM from continuously generating the noisy alerts, failing to address the root cause of the high volume.

  • ✓

    Create a suppression rule for that event ID

    Why this is correct

    Implementing a suppression rule allows the SIEM to filter out or silence specific, known-benign event IDs under defined conditions. This directly reduces alert fatigue and noise in the console, allowing analysts to focus on legitimate security threats without losing the underlying log data.

  • ✗

    Disable the SIEM correlation engine

    Why it's wrong here

    Shutting down the correlation engine is an extreme and dangerous measure that halts all real-time threat detection across the entire enterprise. While it would stop the false positives, it also blinds the security team to actual, critical security incidents, severely compromising the organization's defensive posture.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.