CompTIA CySA+ (CS0-003)Security OperationsEasy

A SOC analyst configures a SIEM correlation rule that has been generating dozens of daily alerts for authentication attempts from a company-owned vulnerability scanner. The scanner's IP address and login behavior are well documented and expected. Which action should the analyst take to reduce alert fatigue without weakening detection of real threats?

  1. ACreate an allow list/suppression exception for the scanner's known IP address within the rule
  2. BDelete the historical log data associated with the scanner from the SIEM
  3. CIncrease the SIEM's overall alert severity threshold for all authentication rules
  4. DDisable the correlation rule that generates the authentication alerts entirely
Show answer & explanation

Correct answer: A. Create an allow list/suppression exception for the scanner's known IP address within the rule

Adding a targeted allow list or suppression exception for the known, benign scanner IP eliminates the specific false positives while keeping the underlying detection rule intact for genuine threats.

Why the other options are wrong

  • B. Deleting logs destroys evidence and does not address the underlying tuning problem.
  • C. Raising the global threshold could cause real authentication attacks to go undetected.
  • D. Disabling the rule removes detection capability for real malicious logon attempts too.

Alert Tuning

The process of adjusting SIEM rules (via thresholds, allow lists, or suppression) to reduce false positives while preserving true positive detection.

  • Reduces analyst alert fatigue
  • Should target the specific noisy condition, not disable detection broadly
  • Common techniques: allow lists, threshold adjustment, correlation logic refinement

Memory trick: Tune out the noise, not the alarm.

More Security Operations questions