Courseiva
mediumMultiple Choice

CAS-004 Practice Question: Reduce the mean time to detect (MTTD) for…

A company wants to reduce the mean time to detect (MTTD) for security incidents. Which technology is most effective for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security information and event management (SIEM) with behavior analytics

A SIEM with User and Entity Behavior Analytics (UEBA) is most effective for reducing MTTD because it baselines normal behavior and detects anomalies in real time, enabling early detection of threats. Full disk encryption (B) protects data at rest but does not aid detection. A DLP system (C) focuses on preventing data exfiltration, not broad detection. A NIDS (D) relies on signature matching, which can miss novel or subtle attacks and typically has a higher detection latency than behavior analytics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security information and event management (SIEM) with behavior analytics

    Why this is correct

    SIEM with behaviour analytics correlates logs across sources and baselines normal activity, surfacing anomalies that indicate compromise faster than signature-only tooling. This directly reduces mean time to detect, the metric the company wants to improve.

  • ✗

    Full disk encryption software

    Why it's wrong here

    Full disk encryption protects data at rest on a device, producing no detection telemetry, so it cannot reduce MTTD. It is tempting because it is a security control, and it would be correct for preventing unauthorised reading of a lost or stolen laptop's drive.

  • ✗

    Data loss prevention (DLP) system

    Why it's wrong here

    DLP inspects outbound content to block exfiltration, generating alerts only when data leaves, so it does not shorten detection of intrusions. It is tempting because DLP produces security alerts, and it would be correct for preventing sensitive data from being emailed or copied outside the organisation.

  • ✗

    Network-based intrusion detection system (NIDS)

    Why it's wrong here

    A NIDS monitors network traffic for known attack signatures, but it cannot observe endpoint process behaviour, file changes or credential misuse, so detection remains incomplete. It is tempting because network visibility is broad and passive, yet EDR or SIEM correlation across endpoint and identity telemetry reduces MTTD further.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.