SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address against an administrative account. The SIEM has not generated an alert. Which configuration change would best detect this scenario?
⚠ Common exam trap
A common mix-up: candidates confuse the roles of IDS/IPS and SIEM, mistakenly thinking signature-based or host-based IDS can natively correlate login failures from a single source, when in fact SIEM correlation rules are specifically designed for this multi-event behavioral detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a SIEM correlation rule to alert on multiple failed logins from the same source
A SIEM correlation rule can specifically detect multiple failed login attempts from the same source IP address by aggregating and analyzing log events in real time. Unlike signature-based or host-based IDS solutions, a SIEM correlation rule can be tuned to match this exact behavioral pattern, triggering an alert when the configured threshold (e.g., 5 failures within 10 minutes) is exceeded. This directly addresses the gap where the SIEM failed to generate an alert due to the absence of such a rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable signature-based detection on the IDS
Why it's wrong here
Signature-based IDS matches known attack patterns in network traffic, so it cannot correlate repeated authentication failures against one account from a single source. It is tempting because signatures excel at detecting known exploits and malware payloads, but detecting brute-force login patterns requires the SIEM's threshold or correlation rule on authentication logs.
- ✗
Implement a host-based IDS on the server
Why it's wrong here
A host-based IDS monitors file integrity and local system events on the server, not the pattern of failed logins arriving from a remote IP, so it would not surface this brute-force attempt. It is tempting because HIDS detects local compromise indicators, which suits scenarios involving file tampering or rootkit activity on the host.
- ✓
Create a SIEM correlation rule to alert on multiple failed logins from the same source
Why this is correct
A correlation rule aggregates multiple failed authentication events sharing the same source IP within a defined window, generating an alert that the SIEM's default logging alone does not produce. This directly addresses the brute-force pattern against the administrative account that currently goes undetected.
- ✗
Increase log retention to 1 year
Why it's wrong here
Extending retention preserves logs for later forensic review but generates no alert when the failed logins occur, leaving the SIEM silent. It is tempting because longer retention supports compliance and historical investigations, and would be correct where the requirement is post-incident evidence preservation rather than real-time detection.
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.