hardMultiple Choice
SSCP Practice Question: Has implemented a SIEM solution and wants to…
An organization has implemented a SIEM solution and wants to reduce false positives. Which of the following is the most effective approach?
⚠ Common exam trap
SSCP often tests the difference between reducing false positives (tuning rules) and reducing alert volume (raising thresholds) — candidates pick threshold-raising because it sounds efficient, but it introduces false negatives and is not the most effective approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tune correlation rules to exclude known benign activities
The most effective way to reduce false positives in a SIEM is to tune correlation rules so they exclude known benign activities. False positives occur when rules trigger on legitimate behavior; by refining rule logic (whitelisting trusted IPs, excluding scheduled tasks, adjusting thresholds based on baselines), analysts reduce noise without losing detection of real threats. This is the standard SIEM tuning approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tune correlation rules to exclude known benign activities
Why this is correct
Tuning correlation rules to exclude known benign activity reduces alerts triggered by legitimate behaviour, directly cutting false positives while preserving detection of genuine threats. Raising severity thresholds or disabling rules would suppress true positives, so rule tuning is the targeted approach the stem requires.
- ✗
Increase the number of log sources feeding the SIEM
Why it's wrong here
Adding log sources increases alert volume and correlation noise rather than refining detection logic, so false positives rise. It is tempting because broader visibility genuinely improves coverage, and it is the right choice when blind spots, not alert quality, are the identified problem.
- ✗
Raise the threshold for each correlation rule to reduce alerts
Why it's wrong here
Raising correlation thresholds suppresses alerts indiscriminately, hiding genuine detections alongside false ones without improving rule accuracy. It is tempting because tuning thresholds is legitimate when a specific rule is demonstrably too sensitive, but it is the wrong first step when the underlying detection logic itself needs refinement.
- ✗
Assign more analysts to manually review all alerts
Why it's wrong here
Manual review adds human cost without changing the detection logic generating the false positives, so the underlying noise persists. It is tempting because analyst triage is the correct choice when alert volume is manageable and the goal is faster investigation, not detection accuracy.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.