hardMultiple Select
CS0-003 Practice Question: A SIEM correlation rule for impossible travel is…
A SIEM correlation rule for impossible travel is creating noise from VPN users. Which refinements should improve fidelity? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that disabling identity alerts is a valid refinement, but this would eliminate all identity-based detection, whereas the correct approach is to add context (trusted ranges and secondary signals) to reduce noise without losing detection capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a second signal such as new device, failed MFA, or mailbox rule creation
Requiring a second signal—such as a new device, failed MFA, or mailbox rule creation—adds an additional layer of verification that helps confirm the user's identity and intent. This reduces false positives from VPN users whose IP addresses may change rapidly, as the SIEM can now correlate the impossible travel event with other suspicious activities that indicate a genuine compromise rather than a legitimate VPN connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all identity alerts
Why it's wrong here
Disabling all identity alerts is an extreme measure that would eliminate critical detection capabilities for various security incidents, not just impossible travel. While it would reduce false positives for this specific rule, it simultaneously creates a significant security gap, allowing actual malicious activity like account compromise, privilege escalation, or data exfiltration to go unnoticed. This approach sacrifices essential visibility for the sake of noise reduction, which is an unacceptable trade-off in a robust security posture.
- ✓
Require a second signal such as new device, failed MFA, or mailbox rule creation
Why this is correct
Requiring a second, corroborating signal significantly enhances the fidelity of an impossible travel alert by reducing false positives. For instance, an impossible travel event combined with a new device registration, multiple failed MFA attempts, or the creation of a suspicious mailbox rule strongly indicates a compromised account rather than a legitimate user action. This multi-factor anomaly detection approach leverages contextual information to differentiate between benign user behavior and genuine threats, making the alert more actionable and reliable.
- ✓
Add trusted VPN egress ranges as named/known locations
Why this is correct
Many organizations utilize VPNs, which can cause legitimate user logins to appear as impossible travel if the user's initial login is from their home IP and a subsequent login is from the VPN's egress IP in a geographically distant location. By defining trusted corporate VPN egress ranges as known locations within the SIEM, the system can correctly attribute these logins to legitimate corporate access, effectively preventing false positive alerts. This method accurately accounts for expected network architecture and user behavior without suppressing actual anomalous activity.
- ✗
Treat every VPN login as malicious
Why it's wrong here
Treating every VPN login as inherently malicious would generate an overwhelming volume of false positive alerts, rendering the SIEM correlation rule ineffective and leading to alert fatigue. VPNs are a standard and legitimate tool for remote access, secure communication, and protecting user privacy, especially in corporate environments. Such an indiscriminate rule would incorrectly flag routine, authorized user activity, making it impossible to distinguish genuine threats from normal operational traffic and severely hindering incident response efforts.
Go deeper
Related to this question
Learn chapter
Lessons Learned and Post-Incident Activities
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.