CS0-003 Security Operations Practice Question
A security analyst reviews a SIEM alert that fired when a user successfully logged into a server from a remote IP address at 3 AM. The user is a system administrator who often works late. What is the most appropriate initial classification of this alert?
⚠ Common exam trap
CS0-004 often tests the distinction between alert classification terms, and the trap is confusing 'false positive' with 'true positive' by assuming any alert that fires is a true positive, or misinterpreting 'true negative' as a correct non-alert.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
False positive
The alert is a false positive because the SIEM rule triggered on a legitimate login that matches the pattern of an authorized after-hours admin session. The user is a system administrator who often works late, so the activity is expected and benign. A true positive would require the login to be malicious or unauthorized, which is not the case here. Since the alert fired but the underlying activity is not a security incident, it is correctly classified as a false positive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
False positive
Why this is correct
This scenario represents a false positive because the SIEM's correlation rules triggered an alert on benign, authorized user activity. The system incorrectly classified a legitimate login attempt as a security threat, requiring the analyst to investigate and potentially tune the rule to prevent future noise.
- ✗
True positive
Why it's wrong here
A true positive occurs when a security control correctly identifies and alerts on actual malicious behavior or an active policy violation. Because the analyst determined that the login was legitimate and authorized, no actual threat existed, meaning this classification is incorrect.
- ✗
True negative
Why it's wrong here
In a true negative scenario, benign activity occurs and the SIEM correctly ignores it without generating any alerts. Since an alert was actively generated by the system in this case, the event cannot be classified as a true negative.
- ✗
False negative
Why it's wrong here
A false negative represents a critical security failure where malicious activity bypasses detection mechanisms entirely without triggering an alert. This does not apply here because an alert was successfully generated, and the underlying event was benign rather than malicious.
Go deeper
Related to this question
Learn chapter
NIST Incident Response Framework
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.