CAS-004 Security Operations Practice Question
A security operations center (SOC) analyst receives an alert from the SIEM indicating a user has logged into the corporate VPN from an unusual geographic location at 3 AM, which is outside the user's normal working hours. The user has not previously exhibited this behavior. Which advanced SIEM capability is most likely responsible for generating this alert?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User Behavior Analytics (UBA)
User Behavior Analytics (UBA) uses machine learning to establish a baseline of normal user activity and detect anomalies such as unusual login times and locations. This is a core feature of advanced SIEM platforms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
User Behavior Analytics (UBA)
Why this is correct
User Behaviour Analytics baselines each user's normal login patterns — location, time, device — and flags statistically anomalous deviations. The 3 AM foreign VPN login falls outside the established baseline, so UBA generates the alert rather than static correlation rules.
- ✗
Correlation rule based on static thresholds
Why it's wrong here
A static threshold rule fires on fixed values such as failed logon counts, not on deviation from a user's own historical login location and time. It is tempting because threshold correlation is simple to configure and effective for volumetric attacks like brute force, where absolute counts genuinely indicate malicious activity.
- ✗
Signature-based detection
Why it's wrong here
Signature-based detection matches known attack patterns or indicators, so a novel login from an unfamiliar location with no prior signature produces no match. It is tempting because signatures reliably catch documented malware and exploits, and would be correct when the activity matches a known threat pattern.
- ✗
Threat intelligence feed correlation
Why it's wrong here
Threat intelligence correlation matches observed IPs, domains or hashes against known-bad indicators; an unusual but unlisted login location carries no such indicator. It is tempting because feeds excel at flagging traffic to known command-and-control infrastructure, which is the right choice when indicators exist.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.