hardMultiple SelectObjective-mapped
CAS-004 Practice Question: A security architect is evaluating a new SIEM…
A security architect is evaluating a new SIEM solution for a large enterprise. Which THREE of the following capabilities are CRITICAL for effective threat detection and response? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse SIEM capabilities with adjacent security tools (vulnerability scanners, patch managers), forgetting that SIEMs are primarily for detection and correlation, not active remediation or scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Real-time correlation of events from multiple sources
Real-time correlation of events from multiple sources is critical because it enables the SIEM to aggregate and analyze logs from diverse systems (firewalls, endpoints, servers) simultaneously, identifying complex attack patterns like lateral movement or multi-stage exploits that would be invisible in isolated logs. This capability directly supports timely detection and automated response, which is the core function of a SIEM in a large enterprise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Real-time correlation of events from multiple sources
Why this is correct
Correlation is essential for identifying patterns and threats.
- ✗
Scheduled vulnerability scanning
Why it's wrong here
Vulnerability scanning is typically performed by dedicated tools, not SIEM.
- ✗
Automated patch management
Why it's wrong here
Patch management is a separate function, not typically part of SIEM.
- ✓
Integration with threat intelligence feeds
Why this is correct
Threat intelligence enriches alerts and improves detection.
- ✓
User and entity behavior analytics (UEBA)
Why this is correct
UEBA detects anomalies in behavior, a key component of modern SIEM.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.