CAS-004 Security Operations Practice Question
A senior security architect is designing a detection strategy for advanced persistent threats (APTs) that employ living-off-the-land (LotL) techniques. Which THREE of the following approaches are most effective for detecting LotL activities? (Choose three.)
⚠ Common exam trap
CAS-005 often tests the misconception that signature-based detection is effective against LotL, when in fact LotL uses legitimate binaries that evade hash-based detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User and Entity Behavior Analytics (UEBA)
Option A (UEBA) is correct because LotL attacks abuse legitimate credentials and tools, so baselining normal user and entity behavior and flagging anomalies (e.g., unusual process lineage, off-hours privileged activity) is one of the few ways to surface attacker activity that leaves no malicious binary. Option B (honeytokens and honeypots) is correct because decoy credentials, files, and hosts have no legitimate use, so any interaction with them is high-fidelity evidence of an intruder performing reconnaissance or lateral movement with native tooling. Option D (monitoring native tool usage with EDR and command-line argument logging) is correct because LotL techniques rely on built-in binaries such as PowerShell, WMI, certutil, and rundll32, and capturing process creation with full command lines (e.g., via Sysmon Event ID 1 or EDR telemetry) exposes suspicious invocations like encoded PowerShell or certutil -urlcache. Option C is not correct because signature-based detection on known malicious file hashes cannot detect LotL activity, which by definition uses already-installed, signed, legitimate system binaries that have no malicious hash. Option E is not correct because blanket blocking of all scripts and macros is a preventive hardening control, not a detection approach, and it is impractical and would not identify an adversary already operating with native tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
User and Entity Behavior Analytics (UEBA)
Why this is correct
LotL attacks abuse legitimate native tools, so signature and IOC matching fail. UEBA establishes behavioural baselines and flags deviations such as unusual tool invocation, odd hours or atypical data access, detecting misuse of trusted binaries without relying on known malware indicators.
- ✓
Deploying honeytokens and honeypots
Why this is correct
Honeytokens and honeypots present attractive decoy credentials, files and hosts that legitimate users never touch. Any interaction generates a high-fidelity alert, exposing an adversary's reconnaissance or lateral movement through native tools, which satisfies the need to detect stealthy LotL activity.
- ✗
Signature-based detection on malicious file hashes
Why it's wrong here
LotL techniques reuse legitimate signed binaries, so file-hash signatures rarely match anything malicious; detection needs behavioural analytics over process lineage and command lines. It is tempting because signature scanning is a familiar, low-noise control, and would be correct against known malware with stable, previously catalogued hashes.
- ✓
Monitoring for native tool usage with EDR and logging command-line arguments
Why this is correct
LotL activity relies on legitimate binaries such as PowerShell, certutil or wmic, so command-line arguments reveal malicious intent. EDR process-level telemetry with full command-line logging captures those invocations, satisfying the requirement to detect abuse of native tools that signature-based monitoring would miss.
- ✗
Blocking all scripts and macros by default
Why it's wrong here
Blocking scripts and macros by default is prevention, not detection, and LotL activity abuses signed native binaries such as PowerShell and WMI that policy cannot simply forbid. It is tempting because script blocking does reduce attack surface, and would be correct as a hardening control rather than a detection strategy.
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.