Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A SIEM alert is generated for a user who logged into a workstation at 2:00 AM, which is outside their normal working hours. The user's manager confirms the user was on call and had legitimate reason to log in. How should the analyst classify this alert?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False positive

The alert is a false positive because the activity is legitimate despite being outside normal hours.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    False positive

    Why this is correct

    This scenario represents a false positive because the SIEM generated an alert for a standard, benign user login. The detection rule incorrectly flagged normal, authorized workstation access as a potential security incident, requiring analysts to investigate and tune the rule to reduce noise.

  • ✗

    False negative

    Why it's wrong here

    A false negative occurs when an actual malicious event or security breach bypasses detection mechanisms entirely, resulting in no alert being generated. Because the SIEM did trigger an alert in this scenario, and the underlying activity was benign rather than harmful, this classification is incorrect.

  • ✗

    True positive

    Why it's wrong here

    For an event to be classified as a true positive, the SIEM must successfully alert on actual malicious or unauthorized activity, such as an active brute-force attack. Since the user's login was legitimate and harmless, the alert was a mistake rather than a successful detection of a threat.

  • ✗

    True negative

    Why it's wrong here

    A true negative describes a state where benign activity occurs and the security monitoring system correctly ignores it without generating any alert. Because the SIEM did fire an alert for this normal workstation login, the system failed to remain silent, ruling out a true negative outcome.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.