GSEC Log Management and SIEM Practice Question
A security analyst is tuning a Splunk Enterprise correlation search that detects brute-force attempts against SSH. The current search fires thousands of alerts daily because it counts every failed password event, including those from a single user who mistypes a password once. The analyst needs to reduce noise while still catching distributed brute-force attacks. Which modification should the analyst make to the correlation search?
⚠ Common exam trap
The trap here is assuming that a simple per-source-IP threshold will catch all brute-force attacks, when distributed attacks deliberately use many IPs to stay under such thresholds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate failed logins across multiple source IPs by counting distinct source IPs per target account over a longer window, and trigger when the distinct count exceeds a threshold.
Distributed brute-force attacks spread login attempts across many source IPs to evade per-IP thresholds. The effective detection method is to correlate failed logins by target account and count distinct source IPs over a longer period. This catches the attack while ignoring a single user's occasional mistyped password, reducing false positives without missing the distributed pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a threshold condition that triggers only when more than 10 failed logins occur from the same source IP within 5 minutes.
Why it's wrong here
Thresholding by a single source IP within a short window is a common tuning step, but it does not address distributed brute-force attacks where each source IP generates only a few failures. It also fails to reduce noise from a single user who mistypes a password once, because that event still counts as one failure and would not meet the threshold, but the search would still evaluate each event. The scenario specifically requires catching distributed attacks, so this approach is insufficient.
- ✓
Correlate failed logins across multiple source IPs by counting distinct source IPs per target account over a longer window, and trigger when the distinct count exceeds a threshold.
Why this is correct
This approach directly addresses distributed brute-force attacks, where many source IPs each try a few passwords against the same account. By counting distinct source IPs per target account over a longer window, the search detects the attack pattern while ignoring isolated mistyped passwords from a single user. It reduces false positives because a single user typically fails from one or two IPs, not many, and it still catches the distributed behavior.
- ✗
Increase the search time window to 24 hours and lower the alert threshold to 5 failed logins per user.
Why it's wrong here
Extending the time window and lowering the threshold would likely increase the number of alerts, not reduce them. A longer window captures more legitimate failures, and a lower threshold makes it easier to trigger on benign activity such as a user who mistypes a password a few times. This tuning direction is opposite to what the analyst needs, and it does not specifically target distributed brute-force patterns.
- ✗
Filter out all failed password events for service accounts and only alert on failed logins for interactive user accounts.
Why it's wrong here
Filtering out service account failures ignores a critical attack vector, because attackers often target service accounts with brute-force attempts. This change would reduce noise only if the noise originated from service accounts, which the scenario does not state. More importantly, it does not help detect distributed brute-force attacks against interactive accounts, so it fails to meet the requirement of catching distributed attacks while reducing false positives.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.