CS0-003 Security Operations Practice Question
A security team is tuning a SIEM rule that alerts on all outbound connections to IP addresses classified as 'high risk' by threat intelligence. The rule generates many false positives because some legitimate services use these IPs. Which two actions should the analyst take to reduce false positives? (Select TWO.)
⚠ Common exam trap
CS0-004 often tests whether candidates choose the 'do nothing' or 'disable' options as shortcuts, when the correct answer is always a targeted tuning action (threshold adjustment or exclusion) that preserves detection while reducing noise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the risk score threshold to only alert on very high risk IPs
Option B is correct because raising the risk score threshold so the rule only fires on 'very high risk' IPs narrows the alert set to indicators with stronger threat-intelligence confidence, filtering out lower-confidence 'high risk' entries that frequently match legitimate services. Option D is correct because adding the verified legitimate IP addresses to an exclusion list (allowlist) suppresses alerts for known-good destinations while keeping detection coverage for the remaining high-risk IPs. Option A is wrong because ignoring false positives leaves the rule noisy and risks missing true malicious connections. Option C is wrong because expanding the rule to include all risky IPs would increase, not reduce, false positives. Option E is wrong because disabling the rule eliminates detection entirely, creating a blind spot rather than tuning the rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the false positives and continue
Why it's wrong here
Leaving the rule untouched means the same legitimate services keep triggering alerts, so the false-positive volume never falls and analysts risk alert fatigue. It is tempting when teams lack tuning time, but ignoring alerts is only defensible once the rule has been scoped with allowlists or threat-intelligence refinements.
- ✓
Increase the risk score threshold to only alert on very high risk IPs
Why this is correct
Raising the risk score threshold means only IPs with very high threat-intelligence risk scores trigger alerts, filtering out lower-scored IPs that legitimate services use. This directly reduces the false positives described in the stem while retaining detection of genuinely high-risk connections.
- ✗
Expand the rule to include all risky IPs
Why it's wrong here
Broadening the rule to cover every risky IP increases the number of matching connections, so false positives rise rather than fall. It is tempting because wider coverage sounds like stronger detection, and expanding scope is correct when the goal is catching more threat infrastructure, not suppressing known-benign traffic.
- ✓
Add known legitimate IP addresses to an exclusion list
Why this is correct
An exclusion list suppresses alerts for specific IP addresses already verified as legitimate services, so their outbound connections no longer generate false positives. This directly addresses the stem's cause of false positives without lowering the rule's sensitivity to unknown high-risk IPs.
- ✗
Disable the rule
Why it's wrong here
Disabling the rule eliminates every alert, including true positives from genuine malicious outbound connections, leaving the organisation blind to the activity it was built to catch. It is tempting as an immediate way to silence noise, and disabling is correct only when a rule is wholly obsolete or duplicated by another control.
Go deeper
Related to this question
Learn chapter
Security Posture Reporting and Dashboards
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.