Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

A senior security architect is designing a detection strategy for advanced persistent threats (APTs) that employ living-off-the-land (LotL) techniques. Which THREE of the following approaches are most effective for detecting LotL activities? (Choose three.)

⚠ Common exam trap

CAS-005 often tests the misconception that signature-based detection is effective against LotL, when in fact LotL uses legitimate binaries that evade hash-based detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User and Entity Behavior Analytics (UEBA)

Option A (UEBA) is correct because LotL attacks abuse legitimate credentials and tools, so baselining normal user and entity behavior and flagging anomalies (e.g., unusual process lineage, off-hours privileged activity) is one of the few ways to surface attacker activity that leaves no malicious binary. Option B (honeytokens and honeypots) is correct because decoy credentials, files, and hosts have no legitimate use, so any interaction with them is high-fidelity evidence of an intruder performing reconnaissance or lateral movement with native tooling. Option D (monitoring native tool usage with EDR and command-line argument logging) is correct because LotL techniques rely on built-in binaries such as PowerShell, WMI, certutil, and rundll32, and capturing process creation with full command lines (e.g., via Sysmon Event ID 1 or EDR telemetry) exposes suspicious invocations like encoded PowerShell or certutil -urlcache. Option C is not correct because signature-based detection on known malicious file hashes cannot detect LotL activity, which by definition uses already-installed, signed, legitimate system binaries that have no malicious hash. Option E is not correct because blanket blocking of all scripts and macros is a preventive hardening control, not a detection approach, and it is impractical and would not identify an adversary already operating with native tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    User and Entity Behavior Analytics (UEBA)

    Why this is correct

    LotL attacks abuse legitimate native tools, so signature and IOC matching fail. UEBA establishes behavioural baselines and flags deviations such as unusual tool invocation, odd hours or atypical data access, detecting misuse of trusted binaries without relying on known malware indicators.

  • ✓

    Deploying honeytokens and honeypots

    Why this is correct

    Honeytokens and honeypots present attractive decoy credentials, files and hosts that legitimate users never touch. Any interaction generates a high-fidelity alert, exposing an adversary's reconnaissance or lateral movement through native tools, which satisfies the need to detect stealthy LotL activity.

  • ✗

    Signature-based detection on malicious file hashes

    Why it's wrong here

    LotL techniques reuse legitimate signed binaries, so file-hash signatures rarely match anything malicious; detection needs behavioural analytics over process lineage and command lines. It is tempting because signature scanning is a familiar, low-noise control, and would be correct against known malware with stable, previously catalogued hashes.

  • ✓

    Monitoring for native tool usage with EDR and logging command-line arguments

    Why this is correct

    LotL activity relies on legitimate binaries such as PowerShell, certutil or wmic, so command-line arguments reveal malicious intent. EDR process-level telemetry with full command-line logging captures those invocations, satisfying the requirement to detect abuse of native tools that signature-based monitoring would miss.

  • ✗

    Blocking all scripts and macros by default

    Why it's wrong here

    Blocking scripts and macros by default is prevention, not detection, and LotL activity abuses signed native binaries such as PowerShell and WMI that policy cannot simply forbid. It is tempting because script blocking does reduce attack surface, and would be correct as a hardening control rather than a detection strategy.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.