About this interactive
Every monitoring module teaches what a SIEM does — it collects logs from everywhere, correlates them, and raises an alert when a rule matches. What almost no module teaches is the job that actually exists on the other side of that alert, which is deciding what the alert is worth before anything else can happen to it. That decision is where security operations either works or drowns. An analyst who escalates everything burns the on-call engineer out in a week and gets ignored. An analyst who closes everything that looks routine will close the one that was not. Both failures come from the same habit: grading the rule name instead of reading the context underneath it. This set is thirty SIEM alerts, each presented with the context cards a real analyst would have open beside it — what the host is for, whose account it is and what privilege it holds, the time of day, whether a change record covers it, and what ninety days of baseline says is normal for that host and that user. Three verdicts, and a rubric stated up front so the answer is defensible rather than a matter of taste. True positive means the rule fired on exactly the activity it names and the evidence in hand already establishes that the activity is unauthorized. False positive means the alert does not survive its own context — the rule matched something it was never built to match, or the activity has a documented, verified benign cause. Needs investigation means the activity is real and unexplained and the evidence genuinely does not settle it, so the correct move is collecting the one fact that would. That third bucket is the one students find hardest and the one that matters most, because the discipline being taught is refusing to promote an alert the evidence does not support and refusing to close one just because it looks familiar. The pool is built in deliberate pairs so the rule name can never produce the verdict. A failed-logon burst is a true positive when one external address tries a single password against 480 accounts, staying under the lockout threshold, and three of them work; it is a false positive when sixty failures come from one host in four minutes beginning at the exact second an approved service-account password rotation started, and stop when the stored credential updates. A port scan is a false positive from the inventoried vulnerability scanner in its approved monthly window, needs investigation from a developer's laptop scanning the developer subnet at two in the afternoon, and a true positive when a finance workstation maps 254 addresses of the server VLAN at 03:12 with the user logged out and the scanning process running from a roaming profile. Impossible travel is a false positive when both addresses are corporate VPN egress carrying the same device identifier and the same session token, and a true positive when the second session registers a new multi-factor method and an external mail forwarding rule filtered on the word invoice within four minutes. Large egress is a false positive from the backup server to the contracted provider on its two-year schedule, needs investigation from a marketing workstation to a nine-year-old commercial transfer service that no policy covers, and a true positive from an employee in their notice period who bulk-read 3,100 finance files twenty minutes before uploading 14 GB to personal cloud storage overnight. Facing the student with the same rule name twice and a different answer each time is the entire design, because it makes a wrong answer diagnosable: whoever gets one of a pair wrong skipped a specific clue, and the clue has a name. The false positives are chosen to be the ones that recur in every real environment rather than invented ones — an untuned vendor rule matching the English word select in a search box, a DLP rule matching the card brands' own published test numbers in a test fixture, a failed NTP client whose seven-hour clock drift turns business-hour logons into an out-of-hours alert, a software-distribution agent writing autorun keys on 300 hosts under an approved change. Each of those closes with a tuning action rather than just a close, because an untuned rule charges the same hour to every analyst who comes after. Addresses standing in for external hosts come from the RFC 5737 documentation ranges, which cannot route; internal addressing is RFC 1918; no real card number, hash or domain is asserted anywhere. Ten alerts resolve each way and the correct answer sits in each of the three positions exactly ten times, so a student who always picks the first option scores 33 percent and learns nothing, which is the point. Run it after the module lessons on logging, alerting and baselines, and again after the wrap: twelve drawn from thirty means two consecutive rounds overlap without repeating, and the alerts that fooled you the first time come back.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →