CAS-004 Security Operations Practice Question
A security operations center (SOC) is evaluating a new EDR solution. Which three capabilities are essential for effective endpoint detection and response? (Select THREE).
⚠ Common exam trap
The trap is selecting vulnerability scanning or firewall management because they sound security-related, but the exam expects you to distinguish EDR's host-centric detect/respond triad from adjacent network or vulnerability management functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Behavioral analysis to detect anomalies
Option B is correct because behavioral analysis is the core of EDR: it baselines normal process, file, registry, and network activity and flags deviations (e.g., anomalous parent-child process chains, suspicious PowerShell usage) that signature-based tools miss, enabling detection of unknown or fileless threats. Option C is correct because EDR must not only detect but respond; automated containment capabilities such as isolating the host from the network, terminating or suspending malicious processes, and quarantining files are essential to stop lateral movement and reduce dwell time. Option D is correct because continuous, real-time telemetry collection from endpoints (process creation, command-line arguments, file and registry modifications, network connections) is the foundational data source that feeds both detection analytics and post-incident investigation. Option A is not correct because network firewall management is a network-perimeter control, not an endpoint detection and response capability, even though EDR may integrate with firewalls for containment. Option E is not correct because vulnerability scanning identifies known weaknesses for patch prioritization and is typically a separate VM tool, not a core EDR detection-and-response function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network firewall management
Why it's wrong here
Network firewall management governs perimeter traffic filtering, not endpoint process-level visibility. EDR requires continuous endpoint telemetry, behavioural detection and response actions like isolation. It tempts because firewalls and EDR both feed a SOC, yet firewall rule administration sits outside the endpoint agent's detection and response scope.
- ✓
Behavioral analysis to detect anomalies
Why this is correct
Behavioural analysis continuously baselines normal endpoint activity and flags deviations, catching fileless malware and living-off-the-land techniques that signature matching misses. This satisfies the SOC's need for detection beyond known indicators, enabling EDR to surface novel threats in real time rather than waiting for updated signatures.
- ✓
Automated containment of malicious processes
Why this is correct
Automated containment isolates compromised endpoints or kills malicious processes without waiting for analyst action, directly satisfying the SOC's need for rapid threat neutralisation. EDR's core value lies in this response capability: detecting malicious behaviour then immediately restricting its spread, reducing dwell time and limiting lateral movement before human responders engage.
- ✓
Real-time monitoring of endpoint activities
Why this is correct
Real-time monitoring continuously collects process, file and network telemetry from endpoints, supplying the raw data detection engines analyse. This satisfies the SOC's need for ongoing visibility, which is the prerequisite for any detection or response action.
- ✗
Vulnerability scanning of endpoints
Why it's wrong here
Vulnerability scanning identifies missing patches and misconfigurations on a schedule; EDR instead requires continuous behavioural telemetry, detection analytics and response actions such as isolation. It tempts because both are endpoint security controls, but scanning is a preventive assessment capability, not detection and response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.