Your SIEM rule alerts when one account authenticates successfully to multiple servers within 10 minutes. Daily admin patching triggers many alerts, but you must keep visibility into true lateral movement. Which rule change best improves precision?
Select an answer to reveal the explanation.
Short Explanation
Think of a correlation rule like a metal detector: if it beeps for every key, you stop listening. Add a second clue, like remote service creation, so benign admin logons stop drowning the real hunt. You keep the useful noise and still catch an attacker moving sideways.
Full Explanation
The correct tuning approach is correlation enrichment: keep the original authentication pattern as one signal, but require a second, independent lateral-movement indicator such as remote service creation, scheduled task creation, admin share access, or remote command-shell behavior. Benign administrative patching often produces many logons but not the full kill chain, so the second condition filters noise while preserving alerts when an attacker actually moves from one host to another. Raising the number of required logons only lowers sensitivity; an attacker who compromises one account and touches a few hosts may no longer alert. Allow-listing administrative jump hosts or service accounts is dangerous because those same hosts are common paths for true lateral movement, so an attacker could blend into the approved baseline. Suppressing alerts from privileged group membership removes the most important attacker population and creates a blind spot. Moving the rule to a single-event alert for any admin logon increases volume and destroys precision. Exam caveat: CompTIA expects tuning that improves signal quality through contextual correlation, not broad suppression. Operational check: replay the last seven days of alerts against the modified rule and confirm that known patching jobs stop alerting while documented lateral-movement test events still fire.