GSEC Log Management and SIEM Practice Question
An analyst notices that the SIEM is triggering an excessive number of 'False Positive' alerts related to failed login attempts. Which strategy is most effective for reducing these alerts without compromising security posture?
⚠ Common exam trap
Candidates suggest disabling logging entirely or increasing log retention periods, which either blinds the security team or fails to reduce active alert noise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a threshold-based correlation rule to alert only after five failed attempts within one minute.
Tuning the SIEM to filter noise is critical for preventing analyst fatigue and ensuring high-fidelity alerts remain visible. By creating suppression rules for known service account behavior or implementing threshold-based alerts, analysts can focus on genuine threats. This process is essential for maintaining a healthy SIEM environment where security teams can respond efficiently to legitimate incidents rather than chasing benign log noise generated by standard system maintenance tasks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all failed login logging on domain controllers to save SIEM storage.
Why it's wrong here
Disabling logging entirely blinds the security team to brute-force attacks and unauthorized access attempts. This approach violates the principle of least privilege and eliminates visibility into credential-based threats, rendering the SIEM ineffective for detecting account compromise or lateral movement activities within the enterprise network infrastructure.
- ✗
Increase the severity level of all login failure logs to 'Critical'.
Why it's wrong here
Changing the severity level does not reduce the volume of incoming log data or the frequency of alerts triggered. It simply reclassifies the noise, which complicates incident prioritization and potentially causes analysts to miss actual high-priority security incidents buried within a high volume of incorrectly prioritized alerts.
- ✓
Implement a threshold-based correlation rule to alert only after five failed attempts within one minute.
Why this is correct
Threshold-based alerting filters out transient, single-instance failures caused by mistyped passwords or minor sync issues. By requiring multiple failures in a short duration, the system ignores common user errors while still catching automated brute-force attacks, successfully balancing signal fidelity with the need for continuous security monitoring and oversight.
- ✗
Archive all failed login logs to cold storage immediately upon ingestion.
Why it's wrong here
Moving logs to cold storage prevents the SIEM correlation engine from processing them in real-time. This action makes it impossible for the SIEM to identify patterns of attack or trigger automated responses, defeating the primary purpose of having a centralized log management and security information system.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.