CAS-004 Security Architecture Practice Question
A company is modernizing its security operations center and wants to correlate logs from firewalls, endpoints, and cloud services in a single platform that supports long-term retention and custom detection rules. Which technology best fits this requirement?
⚠ Common exam trap
The trap here is choosing a tool that produces security-relevant data, such as a vulnerability scanner, when the requirement is a platform that ingests and correlates logs from many sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A security information and event management (SIEM) platform.
The described need is centralized ingestion, normalization, correlation, retention, and custom detection across many log sources, which is the core purpose of a SIEM. Vulnerability scanners, network performance monitors, and configuration databases each serve different operational functions and none provides the combined correlation and retention capability required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A network performance monitoring (NPM) appliance.
Why it's wrong here
NPM appliances focus on bandwidth, latency, and application performance across the network. While they may collect flow data, they are not designed to normalize security telemetry from endpoints and cloud services, correlate it into detections, or retain logs for compliance and investigation, so they do not meet the stated requirement.
- ✗
A vulnerability management scanner.
Why it's wrong here
A vulnerability scanner identifies missing patches and configuration weaknesses on hosts and applications. It does not ingest and correlate operational logs from firewalls, endpoints, and cloud services, nor does it provide long-term log retention or custom detection rules, so it addresses a different function than the one described.
- ✓
A security information and event management (SIEM) platform.
Why this is correct
A SIEM collects and normalizes logs from disparate sources such as firewalls, endpoints, and cloud services, correlates events across them, retains data for long-term analysis, and supports custom detection rules and alerts. This directly matches the requirement for centralized correlation, retention, and customizable detections in a security operations center.
- ✗
A configuration management database (CMDB).
Why it's wrong here
A CMDB records relationships and attributes of configuration items such as servers and applications. It supports change management and asset context but does not collect, correlate, or retain security event logs, and it cannot execute custom detection rules, making it unsuitable for the security operations center requirement described.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.