Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

A security operations center (SOC) is evaluating a new EDR solution. Which three capabilities are essential for effective endpoint detection and response? (Select THREE).

⚠ Common exam trap

The trap is selecting vulnerability scanning or firewall management because they sound security-related, but the exam expects you to distinguish EDR's host-centric detect/respond triad from adjacent network or vulnerability management functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Behavioral analysis to detect anomalies

Option B is correct because behavioral analysis is the core of EDR: it baselines normal process, file, registry, and network activity and flags deviations (e.g., anomalous parent-child process chains, suspicious PowerShell usage) that signature-based tools miss, enabling detection of unknown or fileless threats. Option C is correct because EDR must not only detect but respond; automated containment capabilities such as isolating the host from the network, terminating or suspending malicious processes, and quarantining files are essential to stop lateral movement and reduce dwell time. Option D is correct because continuous, real-time telemetry collection from endpoints (process creation, command-line arguments, file and registry modifications, network connections) is the foundational data source that feeds both detection analytics and post-incident investigation. Option A is not correct because network firewall management is a network-perimeter control, not an endpoint detection and response capability, even though EDR may integrate with firewalls for containment. Option E is not correct because vulnerability scanning identifies known weaknesses for patch prioritization and is typically a separate VM tool, not a core EDR detection-and-response function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network firewall management

    Why it's wrong here

    Network firewall management governs perimeter traffic filtering, not endpoint process-level visibility. EDR requires continuous endpoint telemetry, behavioural detection and response actions like isolation. It tempts because firewalls and EDR both feed a SOC, yet firewall rule administration sits outside the endpoint agent's detection and response scope.

  • ✓

    Behavioral analysis to detect anomalies

    Why this is correct

    Behavioural analysis continuously baselines normal endpoint activity and flags deviations, catching fileless malware and living-off-the-land techniques that signature matching misses. This satisfies the SOC's need for detection beyond known indicators, enabling EDR to surface novel threats in real time rather than waiting for updated signatures.

  • ✓

    Automated containment of malicious processes

    Why this is correct

    Automated containment isolates compromised endpoints or kills malicious processes without waiting for analyst action, directly satisfying the SOC's need for rapid threat neutralisation. EDR's core value lies in this response capability: detecting malicious behaviour then immediately restricting its spread, reducing dwell time and limiting lateral movement before human responders engage.

  • ✓

    Real-time monitoring of endpoint activities

    Why this is correct

    Real-time monitoring continuously collects process, file and network telemetry from endpoints, supplying the raw data detection engines analyse. This satisfies the SOC's need for ongoing visibility, which is the prerequisite for any detection or response action.

  • ✗

    Vulnerability scanning of endpoints

    Why it's wrong here

    Vulnerability scanning identifies missing patches and misconfigurations on a schedule; EDR instead requires continuous behavioural telemetry, detection analytics and response actions such as isolation. It tempts because both are endpoint security controls, but scanning is a preventive assessment capability, not detection and response.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.