Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security analyst reviews logs and discovers that a user's account was used to log into the corporate VPN from a foreign country at 3 AM, even though the user was at home in the US and claims they were asleep. Which security control is best designed to detect and alert on this type of anomalous activity?

⚠ Common exam trap

Many exam-takers confuse 'authentication' (MFA) with 'behavioral detection' (UEBA), assuming that because MFA adds a security layer, it would catch location anomalies, but MFA does not evaluate the context of the authentication request.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User and Entity Behavior Analytics (UEBA)

User and Entity Behavior Analytics (UEBA) is specifically designed to establish baselines of normal user behavior (e.g., login times, locations, devices) and then detect deviations from that baseline. In this scenario, a login from a foreign country at 3 AM while the user was asleep in the US is a clear behavioral anomaly that UEBA would flag, triggering an alert. Unlike other controls, UEBA focuses on the 'what is unusual' rather than 'what is unauthorized'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multifactor authentication (MFA)

    Why it's wrong here

    Multifactor authentication (MFA) is a preventive identity control that requires two or more verification factors before granting access, effectively blocking credential-stuffing and many phishing attacks. However, MFA operates only at the instant of authentication; it does not continuously monitor user activity after a session is established. If an attacker has already passed MFA (for example, via session token theft or a phishing one-time code), MFA cannot detect anomalous post-login behavior such as an access from an unusual geographical location. Therefore, MFA is not a detective control and cannot flag the already-anomalous activity recorded in the logs.

  • ✗

    Data Loss Prevention (DLP)

    Why it's wrong here

    Data Loss Prevention (DLP) systems inspect data content and context to enforce policies that prevent unauthorized exfiltration of sensitive information, such as blocking an email containing a credit card number or prohibiting a USB copy of a personnel file. DLP is blind to authentication metadata like login source IP, device fingerprint, or time-of-day patterns because it analyzes payloads, not user identity or session anomalies. While DLP might alert if a compromised user suddenly attempts to transfer terabytes of data, the anomaly in the scenario is a login from an unusual location, which DLP is not designed to observe or report.

  • ✓

    User and Entity Behavior Analytics (UEBA)

    Why this is correct

    User and Entity Behavior Analytics (UEBA) leverages machine learning and statistical modeling to establish a baseline of normal behavior for each user, peer group, and entity, then flags statistically significant deviations such as logins from uncharacteristic countries, impossible travel distances, or access to never-before-used resources. In this scenario, the log review reveals a user login that deviates from established norms, which is precisely the type of post-authentication anomaly UEBA is engineered to detect. UEBA correlates data from SIEMs, identity providers, and endpoints to generate risk scores that aid incident investigators, making it the correct detective control for anomalous account activity.

  • ✗

    Endpoint protection platform (EPP)

    Why it's wrong here

    Endpoint protection platforms (EPP) are preventive security agents installed on devices to detect and block malware, ransomware, and exploits through signatures, heuristics, and occasionally process-based behavioral monitoring. An EPP may observe that a browser process was spawned by Outlook or that PowerShell is making suspicious network connections, but it does not model the identity or login location of the user interacting with the system. Even with some modern behavioral detection, EPP focuses on file, process, and network artifacts rather than user-account context; it would not flag a successful authentication from an unexpected IP as an anomaly. Thus, EPP cannot address the unusual login pattern found in the logs.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.