CAS-004 Security Operations Practice Question
A security operations center (SOC) analyst is tuning a SIEM correlation rule to detect lateral movement using pass-the-hash attacks. The analyst wants to minimize false positives while ensuring detection of true positives. Which approach is most effective for reducing false positives in this scenario?
⚠ Common exam trap
The trap is choosing overly broad rules (like any NTLM) or generic patterns (failed logins) that cause false positives; the question emphasizes minimizing false positives, so behavior baselining is the best answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compare authentication events against a baseline of normal user behavior and alert on anomalies
Comparing authentication events against a baseline of normal user behavior and alerting on anomalies is the most effective approach to reduce false positives while detecting pass-the-hash attacks. Pass-the-hash involves using stolen NTLM hashes to authenticate, often from unusual workstations or at unusual times. A baseline of normal behavior can identify deviations such as a user authenticating from a new workstation or at odd hours, which are strong indicators of compromise. This approach is more precise than blanket rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Alert on any use of NTLM authentication
Why it's wrong here
Alerting on any NTLM use flags every legitimate legacy authentication, producing overwhelming false positives rather than minimising them. It is tempting because NTLM is the protocol pass-the-hash abuses, so it would be correct only as a broad audit of NTLM reliance before a migration, not as a tuned detection rule.
- ✗
Alert on multiple failed logins followed by a successful login from a different workstation
Why it's wrong here
Failed-then-successful logins from a different workstation describe ordinary user error or roaming, not pass-the-hash, which reuses a captured NTLM hash and needs no failed attempts. It is tempting because brute-force and credential-stuffing detection genuinely relies on that failure-then-success pattern, so it would be correct for those attacks.
- ✗
Disable NTLM authentication across the network
Why it's wrong here
Disabling NTLM removes the attack path but is a network-wide configuration change, not SIEM correlation tuning, and breaks legacy applications still requiring NTLM. It is tempting because eliminating the protocol genuinely prevents pass-the-hash; it would be correct as a hardening project rather than a detection-rule adjustment.
- ✓
Compare authentication events against a baseline of normal user behavior and alert on anomalies
Why this is correct
Baselining normal authentication behaviour lets the rule flag deviations such as a single account authenticating to many hosts rapidly, which typifies pass-the-hash lateral movement. This behavioural axis, rather than static signature matching, suppresses benign administrative logons and reduces false positives while retaining true-positive detection.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.