CAS-004 Security Operations Practice Question
A security operations center (SOC) is implementing User Behavior Analytics (UBA) to detect insider threats. Which TWO of the following data sources are most critical for establishing a baseline of normal user behavior?
⚠ Common exam trap
The trap is selecting data sources that seem security-related but are not behavioral, such as threat intelligence feeds or email content. Candidates might also overlook network traffic logs as a key source for behavioral baselining.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication logs from Active Directory
Authentication logs from Active Directory (A) are critical because they capture logon events, logon types, source workstations, and failure patterns (e.g., Event IDs 4624/4625), which directly define each user's normal access times, locations, and habits for UBA baselining. Network traffic logs from firewalls and proxies (C) are equally critical because they reveal each user's typical destinations, protocols, ports, data volumes, and timing, enabling detection of deviations such as large uploads or access to unusual external services. Together, identity/authentication data and network activity data form the core behavioral baseline for insider-threat detection. Threat intelligence feeds (B) describe external adversaries and indicators of compromise, not a given user's normal behavior, so they support threat matching rather than baselining. HR performance reviews (D) are subjective personnel records unrelated to technical behavior patterns. Email content and subject lines (E) are content-level data that raise privacy and legal concerns and are not required to establish behavioral baselines, which rely on metadata and activity patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authentication logs from Active Directory
Why this is correct
Authentication logs from Microsoft Entra ID or Active Directory record who logged on, when, from where and whether attempts failed. These identity events form the core behavioural baseline UBA needs to flag anomalous insider sign-in patterns, such as impossible travel or off-hours access, satisfying the stem's requirement for normal user behaviour data.
- ✗
Threat intelligence feeds
Why it's wrong here
Threat intelligence feeds describe external adversary indicators, not the organisation's own users, so they cannot establish a baseline of normal behaviour. It is tempting because feeds enrich detection and prioritisation, making them valuable for correlating known malicious infrastructure, but UBA baselines require internal activity data such as logons and file access.
- ✓
Network traffic logs from firewalls and proxies
Why this is correct
Firewall and proxy logs capture outbound destinations, volumes and protocols, revealing data exfiltration or command-and-control traffic. Combined with identity data, they establish what normal network behaviour looks like per user, directly satisfying the UBA baseline requirement for insider threat detection.
- ✗
HR records of employee performance reviews
Why it's wrong here
Performance reviews are periodic subjective assessments, not continuous activity telemetry, so they cannot establish a behavioural baseline for UBA. It is tempting because HR data does inform insider-risk scoring, making it relevant to personnel risk programmes, but it records judgements about output rather than measurable user actions.
- ✗
Email content and subject lines
Why it's wrong here
Email content and subject lines are unstructured text, not behavioural telemetry, so they cannot establish a quantitative baseline of normal activity for UBA. It is tempting because content inspection does surface insider intent, making it valuable for data loss prevention or eDiscovery, not for modelling deviation from routine user actions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.