Courseiva
Security Operations →mediumMultiple Select

CS0-003 Security Operations Practice Question

A security team is tuning a SIEM rule that alerts on all outbound connections to IP addresses classified as 'high risk' by threat intelligence. The rule generates many false positives because some legitimate services use these IPs. Which two actions should the analyst take to reduce false positives? (Select TWO.)

⚠ Common exam trap

CS0-004 often tests whether candidates choose the 'do nothing' or 'disable' options as shortcuts, when the correct answer is always a targeted tuning action (threshold adjustment or exclusion) that preserves detection while reducing noise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the risk score threshold to only alert on very high risk IPs

Option B is correct because raising the risk score threshold so the rule only fires on 'very high risk' IPs narrows the alert set to indicators with stronger threat-intelligence confidence, filtering out lower-confidence 'high risk' entries that frequently match legitimate services. Option D is correct because adding the verified legitimate IP addresses to an exclusion list (allowlist) suppresses alerts for known-good destinations while keeping detection coverage for the remaining high-risk IPs. Option A is wrong because ignoring false positives leaves the rule noisy and risks missing true malicious connections. Option C is wrong because expanding the rule to include all risky IPs would increase, not reduce, false positives. Option E is wrong because disabling the rule eliminates detection entirely, creating a blind spot rather than tuning the rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ignore the false positives and continue

    Why it's wrong here

    Leaving the rule untouched means the same legitimate services keep triggering alerts, so the false-positive volume never falls and analysts risk alert fatigue. It is tempting when teams lack tuning time, but ignoring alerts is only defensible once the rule has been scoped with allowlists or threat-intelligence refinements.

  • ✓

    Increase the risk score threshold to only alert on very high risk IPs

    Why this is correct

    Raising the risk score threshold means only IPs with very high threat-intelligence risk scores trigger alerts, filtering out lower-scored IPs that legitimate services use. This directly reduces the false positives described in the stem while retaining detection of genuinely high-risk connections.

  • ✗

    Expand the rule to include all risky IPs

    Why it's wrong here

    Broadening the rule to cover every risky IP increases the number of matching connections, so false positives rise rather than fall. It is tempting because wider coverage sounds like stronger detection, and expanding scope is correct when the goal is catching more threat infrastructure, not suppressing known-benign traffic.

  • ✓

    Add known legitimate IP addresses to an exclusion list

    Why this is correct

    An exclusion list suppresses alerts for specific IP addresses already verified as legitimate services, so their outbound connections no longer generate false positives. This directly addresses the stem's cause of false positives without lowering the rule's sensitivity to unknown high-risk IPs.

  • ✗

    Disable the rule

    Why it's wrong here

    Disabling the rule eliminates every alert, including true positives from genuine malicious outbound connections, leaving the organisation blind to the activity it was built to catch. It is tempting as an immediate way to silence noise, and disabling is correct only when a rule is wholly obsolete or duplicated by another control.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.