Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A security operations center (SOC) is implementing User Behavior Analytics (UBA) to detect insider threats. Which TWO of the following data sources are most critical for establishing a baseline of normal user behavior?

⚠ Common exam trap

The trap is selecting data sources that seem security-related but are not behavioral, such as threat intelligence feeds or email content. Candidates might also overlook network traffic logs as a key source for behavioral baselining.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication logs from Active Directory

Authentication logs from Active Directory (A) are critical because they capture logon events, logon types, source workstations, and failure patterns (e.g., Event IDs 4624/4625), which directly define each user's normal access times, locations, and habits for UBA baselining. Network traffic logs from firewalls and proxies (C) are equally critical because they reveal each user's typical destinations, protocols, ports, data volumes, and timing, enabling detection of deviations such as large uploads or access to unusual external services. Together, identity/authentication data and network activity data form the core behavioral baseline for insider-threat detection. Threat intelligence feeds (B) describe external adversaries and indicators of compromise, not a given user's normal behavior, so they support threat matching rather than baselining. HR performance reviews (D) are subjective personnel records unrelated to technical behavior patterns. Email content and subject lines (E) are content-level data that raise privacy and legal concerns and are not required to establish behavioral baselines, which rely on metadata and activity patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authentication logs from Active Directory

    Why this is correct

    Authentication logs from Microsoft Entra ID or Active Directory record who logged on, when, from where and whether attempts failed. These identity events form the core behavioural baseline UBA needs to flag anomalous insider sign-in patterns, such as impossible travel or off-hours access, satisfying the stem's requirement for normal user behaviour data.

  • ✗

    Threat intelligence feeds

    Why it's wrong here

    Threat intelligence feeds describe external adversary indicators, not the organisation's own users, so they cannot establish a baseline of normal behaviour. It is tempting because feeds enrich detection and prioritisation, making them valuable for correlating known malicious infrastructure, but UBA baselines require internal activity data such as logons and file access.

  • ✓

    Network traffic logs from firewalls and proxies

    Why this is correct

    Firewall and proxy logs capture outbound destinations, volumes and protocols, revealing data exfiltration or command-and-control traffic. Combined with identity data, they establish what normal network behaviour looks like per user, directly satisfying the UBA baseline requirement for insider threat detection.

  • ✗

    HR records of employee performance reviews

    Why it's wrong here

    Performance reviews are periodic subjective assessments, not continuous activity telemetry, so they cannot establish a behavioural baseline for UBA. It is tempting because HR data does inform insider-risk scoring, making it relevant to personnel risk programmes, but it records judgements about output rather than measurable user actions.

  • ✗

    Email content and subject lines

    Why it's wrong here

    Email content and subject lines are unstructured text, not behavioural telemetry, so they cannot establish a quantitative baseline of normal activity for UBA. It is tempting because content inspection does surface insider intent, making it valuable for data loss prevention or eDiscovery, not for modelling deviation from routine user actions.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.