CAS-004 Security Operations Practice Question
A security administrator is configuring a new endpoint detection and response (EDR) solution. The administrator wants to ensure that the EDR agent can detect and block malicious activities in real-time. Which of the following capabilities is MOST essential for the EDR agent to achieve this goal?
⚠ Common exam trap
Many exam-takers confuse SIEM integration or scheduled scans with the real-time monitoring that is fundamental to EDR's detection and blocking capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Continuous monitoring of process and file system activity.
EDR agents must continuously monitor endpoint activities such as process execution, file system changes, and network connections to detect and block malicious behavior in real-time. This telemetry enables behavioral analysis and immediate response. SIEM integration, scheduled scans, and UBA are valuable but do not provide the real-time detection and blocking capability that continuous monitoring offers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Periodic full disk scans scheduled during off-hours.
Why it's wrong here
Periodic scans are useful for detecting dormant threats, but they are not real-time. They do not provide continuous monitoring or immediate blocking of active malicious processes. EDR's strength lies in its real-time behavioral analysis, not scheduled scans. Therefore, this capability is insufficient for the administrator's goal of real-time detection and blocking.
- ✗
Integration with a security information and event management (SIEM) system.
Why it's wrong here
SIEM integration is valuable for centralized logging and correlation, but it is not essential for real-time detection and blocking on the endpoint itself. The EDR agent must first detect malicious activity locally; SIEM integration enhances visibility but does not provide the real-time blocking capability. Thus, it is not the most critical feature for this specific goal.
- ✗
User behavior analytics (UBA) to detect insider threats.
Why it's wrong here
UBA focuses on detecting anomalous user behavior, which is important for insider threat detection, but it is not the primary mechanism for real-time blocking of malicious activities like malware execution. EDR's core real-time capability is endpoint telemetry and behavioral blocking. While UBA can complement EDR, it is not the most essential for the stated goal.
- ✓
Continuous monitoring of process and file system activity.
Why this is correct
EDR solutions rely on continuous monitoring of endpoint activities such as process creation, file modifications, and network connections to detect malicious behavior in real-time. This telemetry is essential for identifying indicators of compromise and triggering automated responses. Without continuous monitoring, the EDR would lack the data needed to detect and block threats as they occur.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.