Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is investigating a potential advanced persistent threat (APT) that has been evading traditional detection. The analyst decides to use User and Entity Behavior Analytics (UEBA) to identify anomalous activity. Which TWO of the following activities would be most indicative of a potential compromise when analyzed through UEBA? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A user logging in from a remote location at 3:00 AM, which is outside their normal working hours

Option B is correct because UEBA baselines each user's normal login behavior, so a login from a remote location at 3:00 AM deviates from that user's established time-of-day and geographic pattern, which is a classic anomaly indicating possible credential compromise or unauthorized access. Option C is correct because UEBA tracks entity-to-resource relationships, and a user suddenly accessing a large volume of files they do not normally touch signals abnormal data access consistent with reconnaissance or exfiltration by an APT. Option A is not indicative because a service account authenticating to a database every 5 minutes is a predictable, recurring pattern that UEBA would learn as normal baseline behavior. Option D is not indicative because connecting to the corporate VPN from a hotel during a business trip is consistent with legitimate, expected remote-work behavior. Option E is not indicative because a scheduled antivirus scan run by an administrator is a routine, authorized administrative task that matches normal baseline activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A service account authenticating to a database server every 5 minutes

    Why it's wrong here

    A service account authenticating to a database every five minutes is a regular, repeating pattern that UEBA baselines as normal behaviour. It is tempting because service accounts are frequent APT targets, and it would be the correct indicator if the interval, source host or query volume deviated from the established baseline.

  • ✓

    A user logging in from a remote location at 3:00 AM, which is outside their normal working hours

    Why this is correct

    UEBA baselines each user's normal login patterns, so a 3:00 AM session from an unusual remote location deviates sharply on time and geolocation axes. That behavioural anomaly indicates possible credential compromise, unlike routine activity matching established patterns.

  • ✓

    A user accessing a large number of files on a file server that they do not normally access

    Why this is correct

    UEBA profiles each user's typical file access volume and repositories, so mass access to files outside their normal scope signals possible data collection or staging. This deviation on the access-pattern axis indicates compromise, distinguishing it from routine file server usage.

  • ✗

    A user connecting to the corporate VPN from a hotel during a business trip

    Why it's wrong here

    VPN access from a hotel during a business trip matches an expected travel pattern, so UEBA baselines would not flag it as anomalous. It is tempting because unusual geolocation can indicate credential theft, and it would be the correct indicator where the same account also authenticates from an implausible second location simultaneously.

  • ✗

    An administrator running a scheduled antivirus scan on a server

    Why it's wrong here

    A scheduled antivirus scan is an authorised, recurring administrative task that UEBA learns as normal for that administrator and server. It is tempting because privileged actions on servers can signal lateral movement, and it would be the correct indicator if the scan ran at an unexpected time or from an unusual host.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.