Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst notices a high number of alerts from a new detection rule that triggers on 'any outbound connection to a known malicious IP'. After investigation, the analyst finds that the IP address is from a threat intelligence feed but the connections are actually from a legitimate security scanner that was recently deployed. How should the analyst handle this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the scanner's IP to an allowlist in the rule

The alerts are false positives because the traffic is legitimate. The analyst should tune the rule to exclude the scanner's source IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the scanner's IP to an allowlist in the rule

    Why this is correct

    Adding the authorized scanner's IP address to an exclusion or allowlist within the specific detection rule suppresses benign alerts generated by scheduled vulnerability assessments. This targeted tuning preserves the rule's efficacy for detecting actual malicious activity from unauthorized sources while eliminating alert fatigue caused by known, legitimate scanning activities.

  • ✗

    Disable the rule permanently

    Why it's wrong here

    Permanently disabling the rule creates a critical blind spot in the organization's security posture by completely removing the capability to detect genuine attacks that leverage the same techniques. Instead of resolving the noise through proper rule tuning, this action leaves the network vulnerable to malicious actors exploiting the unmonitored vector.

  • ✗

    Report the scanner as compromised

    Why it's wrong here

    Reporting the scanner as compromised is an inappropriate response because the high volume of alerts is a predictable result of routine, authorized vulnerability scanning rather than malicious exploitation. Initiating an incident response workflow for a known, benign administrative tool wastes valuable analyst resources and misidentifies legitimate operational traffic as an active threat.

  • ✗

    Increase the severity of the rule

    Why it's wrong here

    Elevating the severity level of the rule does nothing to filter out the benign traffic generated by the scanner; instead, it exacerbates alert fatigue by flooding the SIEM console with high-priority false positives. This misconfiguration can distract security analysts from investigating actual critical incidents that require immediate triage and remediation.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.