nerdexam
CompTIA

CS0-003 · Question #226

An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with…

The correct answer is C. False negative. A false negative is a situation where an attack or a threat is not detected by a security control, even though it should have been. In this case, the SIEM rule was unable to detect an attack with nine failed logins, which is below the threshold of ten failed logins that…

Submitted by fernanda_arg· Mar 6, 2026Security Operations

Question

An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins. Which of the following best represents what occurred?

Options

  • AFalse positive
  • BTrue negative
  • CFalse negative
  • DTrue positive

How the community answered

(37 responses)
  • A
    3% (1)
  • C
    92% (34)
  • D
    5% (2)

Explanation

A false negative is a situation where an attack or a threat is not detected by a security control, even though it should have been. In this case, the SIEM rule was unable to detect an attack with nine failed logins, which is below the threshold of ten failed logins that triggers an alert. This means that the SIEM rule missed a potential attack and failed to alert the security analysts, resulting in a false negative.

Topics

#SIEM#alert tuning#false negative#security monitoring

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice