A security analyst is tuning the SIEM to reduce noise. The current rule fires whenever a Windows event with ID 4625 (failed logon) occurs. Which modification should the analyst make to the rule to better identify a brute-force attack while reducing false positives?
Threshold-based correlation on source IP and time window is a standard SIEM technique to distinguish brute-force attempts from isolated user errors. Ten failures in five minutes from one source exceeds normal human error rates and indicates automated guessing, while ignoring scattered single failures that are typical of mistyped passwords.
Why this answer
Brute-force attacks are characterized by a high volume of failed authentication attempts from a single source in a short period. A threshold-based correlation rule that counts failures per source IP within a time window effectively separates automated attacks from occasional user mistypes, reducing false positives while maintaining detection fidelity.
Exam trap
The trap here is assuming that any filter based on time or account type will reduce false positives without considering that attackers can mimic normal patterns and that high-risk accounts should never be excluded.