Courseiva
Security Operations →easyMultiple Select

CS0-003 Security Operations Practice Question

A security analyst is tuning a SIEM correlation rule that triggers on failed login attempts. The rule is generating a high number of alerts from a specific user who frequently mistypes passwords. The analyst wants to reduce false positives while maintaining detection of brute-force attacks. Which TWO actions should the analyst take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exclude the specific user account from the rule

Increasing the threshold to require more failed attempts in the time window helps ignore simple mistypes, and excluding the specific user account from the rule prevents alerts for that benign behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the correlation rule and create a new one from scratch

    Why it's wrong here

    Deleting the rule removes all existing tuning logic, such as thresholds or exclusion lists, which would discard any progress in reducing false positives from the user’s mistyping. This action is tempting because rebuilding from scratch can be appropriate when the rule’s logic is fundamentally flawed or no longer aligns with the detection requirements, but here the rule itself is functional and only needs adjustment to filter out benign repeated failures while preserving brute-force detection.

  • ✓

    Exclude the specific user account from the rule

    Why this is correct

    By adding an exception or exclusion filter for the specific, known user account within the SIEM correlation logic, the analyst prevents benign, repetitive authentication failures from triggering the alert. This targeted approach directly eliminates false positives generated by this specific user's predictable behavior without degrading the rule's ability to detect brute-force attacks on other accounts.

  • ✓

    Increase the threshold of failed attempts within a time window

    Why this is correct

    Adjusting the correlation rule's threshold—such as requiring 15 failed logins within 5 minutes instead of 5—accommodates minor user typos while maintaining security visibility. This modification filters out transient authentication errors from normal users while ensuring that high-volume, automated brute-force attacks still cross the threshold and trigger an alert.

  • ✗

    Change the rule to alert on every single failed login

    Why it's wrong here

    Configuring the SIEM to alert on every single failed authentication attempt is highly counterproductive, as it floods the security operations center (SOC) with benign events. This dramatic increase in noise leads to severe alert fatigue, making it nearly impossible for analysts to identify actual malicious intrusion attempts amidst the high volume of routine user typos.

  • ✗

    Increase the severity of the rule to trigger an immediate response

    Why it's wrong here

    Elevating the severity level of the alert does nothing to address the underlying logic flaw causing the false positives. Instead, it escalates benign events to a higher priority, unnecessarily distracting incident responders and potentially triggering automated containment actions that disrupt legitimate business operations.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.