Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security team is evaluating an EDR solution. Which of the following capabilities is a primary differentiator between EDR and traditional antivirus?

⚠ Common exam trap

CAS-005 often tests the misconception that EDR is simply 'next-gen antivirus' with signatures plus a cloud console, causing candidates to pick centralized management or signature detection instead of behavioral analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Behavioral analysis and detection

EDR's primary differentiator from traditional antivirus is its use of behavioral analysis and detection. Traditional AV relies on static signatures to identify known malware, whereas EDR continuously records endpoint telemetry (process trees, registry changes, network connections) and applies behavioral heuristics, machine learning, and threat intelligence to detect novel or fileless attacks. This allows EDR to identify malicious activity even when no signature exists, and to provide detection, investigation, and response capabilities rather than just prevention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Centralized policy management

    Why it's wrong here

    Traditional antivirus consoles already push policies to endpoints, so centralised management does not separate EDR from AV. EDR's differentiator is continuous endpoint telemetry collection and behavioural detection with retrospective investigation. Centralised policy management is genuinely useful in large fleets, but it is a shared management feature, not the distinguishing capability.

  • ✗

    File integrity monitoring

    Why it's wrong here

    File integrity monitoring watches changes to critical files and is a host-based intrusion detection function, often delivered by separate HIDS or FIM tools rather than defining EDR. EDR's differentiator is continuous process-level telemetry and behavioural detection. FIM is tempting because it detects tampering, but it does not provide the endpoint activity recording and response that EDR adds.

  • ✗

    Signature-based detection of known malware

    Why it's wrong here

    Signature-based detection of known malware is the core mechanism of traditional antivirus, so it cannot differentiate EDR from AV. EDR adds behavioural analytics and continuous telemetry beyond static signatures. Signatures are tempting because they remain effective against known threats, but they fail against fileless or novel attacks, which is precisely the gap EDR addresses.

  • ✓

    Behavioral analysis and detection

    Why this is correct

    Behavioural analysis and detection distinguishes EDR from signature-based antivirus, which matches only known file hashes. EDR continuously monitors process behaviour, registry changes and API calls, then correlates these events to identify anomalous activity such as living-off-the-land techniques that traditional antivirus, lacking behavioural telemetry, would miss entirely.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.