CS0-003 Security Operations Practice Question
A security analyst is tuning a SIEM correlation rule that generates alerts when a single user logs into more than 10 workstations within 5 minutes. The rule is producing excessive false positives due to service accounts performing automated tasks. Which of the following is the best tuning approach to reduce false positives while still detecting potential lateral movement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an exception for known service account names
Excluding known service accounts from the rule reduces false positives while still detecting lateral movement by user accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the time window to 10 minutes
Why it's wrong here
Adjusting the correlation rule's temporal window to 10 minutes fails to address the root cause of the false positives. Automated service accounts often execute tasks across multiple hosts within seconds, meaning they will easily trigger the rule even within a narrower timeframe. Furthermore, this change risks missing slow-and-low lateral movement attacks that occur over a slightly longer duration.
- ✗
Increase the threshold to 20 workstations
Why it's wrong here
Raising the workstation threshold to 20 hosts severely degrades the SIEM's detection sensitivity, allowing actual attackers to perform lateral movement across up to 19 systems without triggering an alert. Additionally, administrative service accounts routinely touch dozens or hundreds of endpoints during scheduled maintenance windows, meaning this adjustment will not reliably eliminate the false positives.
- ✓
Add an exception for known service account names
Why this is correct
Creating a whitelist or exception within the SIEM correlation rule for validated, non-interactive service accounts is the most effective tuning strategy. This approach eliminates high-volume false positives generated by legitimate automated processes while maintaining strict, low-threshold monitoring for standard user accounts. It ensures that any anomalous lateral movement by human adversaries remains highly visible to the security operations center.
- ✗
Disable the rule and rely on manual log review
Why it's wrong here
Deactivating the correlation rule entirely introduces significant operational risk and represents a poor security posture. Manual log analysis is highly inefficient, prone to human error, and incapable of processing the massive volume of event data generated in modern enterprise environments in real time. This approach effectively blinds the security team to active lateral movement campaigns.
Go deeper
Related to this question
Learn chapter
SOC Tier 1, Tier 2, and Tier 3 Analyst Roles
Key term
Correlation rule
A correlation rule is a set of conditions in a security information and event management (SIEM) system that combines multiple log events from different sources to detect complex threats or patterns that a single event would miss.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.