CAS-004 Security Operations Practice Question
An organization uses a SIEM to collect logs from multiple sources. The security team wants to identify users who are accessing resources outside of normal business hours and exhibiting unusual data transfer patterns. Which advanced SIEM capability would be most effective?
⚠ Common exam trap
CAS-005 often tests the distinction between static, rule-based detection (correlation rules, thresholds) and adaptive, behavior-based analytics (UEBA), so candidates must recognize that 'unusual patterns' and 'outside normal business hours' signal a need for baselining rather than predefined thresholds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User and Entity Behavior Analytics (UEBA)
UEBA (User and Entity Behavior Analytics) is designed to baseline normal behavior for users and entities, then detect statistical deviations such as off-hours access and anomalous data transfer volumes. Unlike static rules, UEBA uses machine learning to model each user's typical login times, peer group activity, and data movement patterns, flagging outliers that would otherwise go unnoticed. This makes it the most effective capability for identifying subtle insider-threat or compromised-account behavior described in the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat intelligence feed integration
Why it's wrong here
Threat intelligence feeds supply known indicators of compromise for matching against logs, so they detect traffic to malicious infrastructure rather than deviations from a user's own normal hours or transfer volumes. Tempting because it enriches detection, it would be correct when the requirement is identifying communication with known malicious IPs, domains or hashes.
- ✓
User and Entity Behavior Analytics (UEBA)
Why this is correct
UEBA baselines each user's and entity's normal activity, then flags statistical deviations such as logons outside business hours and anomalous data volumes. Unlike static correlation rules, it detects subtle, gradual changes in behaviour, directly satisfying the requirement to identify off-hours access and unusual transfer patterns.
- ✗
Log normalization and aggregation
Why it's wrong here
Normalisation and aggregation parse disparate log formats into a common schema and consolidate events, providing the data foundation but performing no behavioural deviation analysis. Tempting because it precedes every detection, it would be correct when the requirement is making heterogeneous sources searchable and reportable, not flagging anomalous user activity.
- ✗
Correlation rules with threshold-based alerts
Why it's wrong here
Threshold-based correlation rules fire on fixed counts within a window, so they cannot model each user's individual baseline of working hours and transfer volumes. Tempting because correlation combines multiple log sources, it would be correct when the requirement is alerting on a known static condition, such as repeated failed logons exceeding a set count.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.