Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst reviews a SIEM alert that fired when a user successfully logged into a server from a remote IP address at 3 AM. The user is a system administrator who often works late. What is the most appropriate initial classification of this alert?

⚠ Common exam trap

CS0-004 often tests the distinction between alert classification terms, and the trap is confusing 'false positive' with 'true positive' by assuming any alert that fires is a true positive, or misinterpreting 'true negative' as a correct non-alert.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False positive

The alert is a false positive because the SIEM rule triggered on a legitimate login that matches the pattern of an authorized after-hours admin session. The user is a system administrator who often works late, so the activity is expected and benign. A true positive would require the login to be malicious or unauthorized, which is not the case here. Since the alert fired but the underlying activity is not a security incident, it is correctly classified as a false positive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    False positive

    Why this is correct

    This scenario represents a false positive because the SIEM's correlation rules triggered an alert on benign, authorized user activity. The system incorrectly classified a legitimate login attempt as a security threat, requiring the analyst to investigate and potentially tune the rule to prevent future noise.

  • ✗

    True positive

    Why it's wrong here

    A true positive occurs when a security control correctly identifies and alerts on actual malicious behavior or an active policy violation. Because the analyst determined that the login was legitimate and authorized, no actual threat existed, meaning this classification is incorrect.

  • ✗

    True negative

    Why it's wrong here

    In a true negative scenario, benign activity occurs and the SIEM correctly ignores it without generating any alerts. Since an alert was actively generated by the system in this case, the event cannot be classified as a true negative.

  • ✗

    False negative

    Why it's wrong here

    A false negative represents a critical security failure where malicious activity bypasses detection mechanisms entirely without triggering an alert. This does not apply here because an alert was successfully generated, and the underlying event was benign rather than malicious.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.