Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst notices repeated alerts for 'DNS query to known malicious domain' from multiple internal hosts. Upon investigation, the analyst finds that the domain is legitimate and used by a third-party service. What should the analyst do to reduce false positives?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the domain to a whitelist in the SIEM

Adding the domain to a whitelist ensures that legitimate traffic is not flagged, reducing false positives without disabling the rule entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the domain to a whitelist in the SIEM

    Why this is correct

    Adding a known-safe, high-volume domain to an exclusion list or whitelist within the SIEM suppresses repetitive false positive alerts without degrading overall detection capabilities. This tuning process optimizes analyst workflow by reducing alert fatigue while preserving the integrity of the underlying correlation rule for other unverified domains.

  • ✗

    Disable the alert rule for DNS queries

    Why it's wrong here

    Deactivating the entire DNS query alert rule creates a critical blind spot, preventing the detection of actual malicious activities such as DNS tunneling, data exfiltration, or command-and-control (C2) communications. Security monitoring must maintain visibility over DNS traffic, making complete disabling of the rule an unacceptable risk.

  • ✗

    Increase the severity of the alert

    Why it's wrong here

    Elevating the severity level of a recurring false positive does not resolve the underlying noise and instead exacerbates alert fatigue for the security operations center (SOC) team. This action misallocates critical triage resources to benign traffic rather than addressing the root cause through proper rule tuning.

  • ✗

    Block the domain on the firewall

    Why it's wrong here

    Implementing a firewall block on a legitimate, frequently queried domain will disrupt business continuity and break application dependencies that rely on that specific external resource. Defensive actions must be proportional and verified, as blocking benign traffic causes self-inflicted denial-of-service conditions.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.