CS0-003 Security Operations Practice Question
A security analyst is tuning a SIEM correlation rule that triggers on failed login attempts. The rule is generating a high number of alerts from a specific user who frequently mistypes passwords. The analyst wants to reduce false positives while maintaining detection of brute-force attacks. Which TWO actions should the analyst take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exclude the specific user account from the rule
Increasing the threshold to require more failed attempts in the time window helps ignore simple mistypes, and excluding the specific user account from the rule prevents alerts for that benign behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the correlation rule and create a new one from scratch
Why it's wrong here
Deleting the rule removes all existing tuning logic, such as thresholds or exclusion lists, which would discard any progress in reducing false positives from the user’s mistyping. This action is tempting because rebuilding from scratch can be appropriate when the rule’s logic is fundamentally flawed or no longer aligns with the detection requirements, but here the rule itself is functional and only needs adjustment to filter out benign repeated failures while preserving brute-force detection.
- ✓
Exclude the specific user account from the rule
Why this is correct
By adding an exception or exclusion filter for the specific, known user account within the SIEM correlation logic, the analyst prevents benign, repetitive authentication failures from triggering the alert. This targeted approach directly eliminates false positives generated by this specific user's predictable behavior without degrading the rule's ability to detect brute-force attacks on other accounts.
- ✓
Increase the threshold of failed attempts within a time window
Why this is correct
Adjusting the correlation rule's threshold—such as requiring 15 failed logins within 5 minutes instead of 5—accommodates minor user typos while maintaining security visibility. This modification filters out transient authentication errors from normal users while ensuring that high-volume, automated brute-force attacks still cross the threshold and trigger an alert.
- ✗
Change the rule to alert on every single failed login
Why it's wrong here
Configuring the SIEM to alert on every single failed authentication attempt is highly counterproductive, as it floods the security operations center (SOC) with benign events. This dramatic increase in noise leads to severe alert fatigue, making it nearly impossible for analysts to identify actual malicious intrusion attempts amidst the high volume of routine user typos.
- ✗
Increase the severity of the rule to trigger an immediate response
Why it's wrong here
Elevating the severity level of the alert does nothing to address the underlying logic flaw causing the false positives. Instead, it escalates benign events to a higher priority, unnecessarily distracting incident responders and potentially triggering automated containment actions that disrupt legitimate business operations.
Go deeper
Related to this question
Learn chapter
Splunk SPL Queries for Security Analysts
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.