Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is tuning a SIEM correlation rule that generates alerts when a single user logs into more than 10 workstations within 5 minutes. The rule is producing excessive false positives due to service accounts performing automated tasks. Which of the following is the best tuning approach to reduce false positives while still detecting potential lateral movement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an exception for known service account names

Excluding known service accounts from the rule reduces false positives while still detecting lateral movement by user accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the time window to 10 minutes

    Why it's wrong here

    Adjusting the correlation rule's temporal window to 10 minutes fails to address the root cause of the false positives. Automated service accounts often execute tasks across multiple hosts within seconds, meaning they will easily trigger the rule even within a narrower timeframe. Furthermore, this change risks missing slow-and-low lateral movement attacks that occur over a slightly longer duration.

  • ✗

    Increase the threshold to 20 workstations

    Why it's wrong here

    Raising the workstation threshold to 20 hosts severely degrades the SIEM's detection sensitivity, allowing actual attackers to perform lateral movement across up to 19 systems without triggering an alert. Additionally, administrative service accounts routinely touch dozens or hundreds of endpoints during scheduled maintenance windows, meaning this adjustment will not reliably eliminate the false positives.

  • ✓

    Add an exception for known service account names

    Why this is correct

    Creating a whitelist or exception within the SIEM correlation rule for validated, non-interactive service accounts is the most effective tuning strategy. This approach eliminates high-volume false positives generated by legitimate automated processes while maintaining strict, low-threshold monitoring for standard user accounts. It ensures that any anomalous lateral movement by human adversaries remains highly visible to the security operations center.

  • ✗

    Disable the rule and rely on manual log review

    Why it's wrong here

    Deactivating the correlation rule entirely introduces significant operational risk and represents a poor security posture. Manual log analysis is highly inefficient, prone to human error, and incapable of processing the massive volume of event data generated in modern enterprise environments in real time. This approach effectively blinds the security team to active lateral movement campaigns.

Go deeper

Related to this question

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.