CS0-003 Security Operations Practice Question
A security analyst notices a high number of alerts from a new detection rule that triggers on 'any outbound connection to a known malicious IP'. After investigation, the analyst finds that the IP address is from a threat intelligence feed but the connections are actually from a legitimate security scanner that was recently deployed. How should the analyst handle this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the scanner's IP to an allowlist in the rule
The alerts are false positives because the traffic is legitimate. The analyst should tune the rule to exclude the scanner's source IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the scanner's IP to an allowlist in the rule
Why this is correct
Adding the authorized scanner's IP address to an exclusion or allowlist within the specific detection rule suppresses benign alerts generated by scheduled vulnerability assessments. This targeted tuning preserves the rule's efficacy for detecting actual malicious activity from unauthorized sources while eliminating alert fatigue caused by known, legitimate scanning activities.
- ✗
Disable the rule permanently
Why it's wrong here
Permanently disabling the rule creates a critical blind spot in the organization's security posture by completely removing the capability to detect genuine attacks that leverage the same techniques. Instead of resolving the noise through proper rule tuning, this action leaves the network vulnerable to malicious actors exploiting the unmonitored vector.
- ✗
Report the scanner as compromised
Why it's wrong here
Reporting the scanner as compromised is an inappropriate response because the high volume of alerts is a predictable result of routine, authorized vulnerability scanning rather than malicious exploitation. Initiating an incident response workflow for a known, benign administrative tool wastes valuable analyst resources and misidentifies legitimate operational traffic as an active threat.
- ✗
Increase the severity of the rule
Why it's wrong here
Elevating the severity level of the rule does nothing to filter out the benign traffic generated by the scanner; instead, it exacerbates alert fatigue by flooding the SIEM console with high-priority false positives. This misconfiguration can distract security analysts from investigating actual critical incidents that require immediate triage and remediation.
Go deeper
Related to this question
Learn chapter
Threat Hunting Techniques and Hypothesis Development
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.