Courseiva

UBA Compromised Account Detection: Three Key Activities

An organization uses User Behavior Analytics (UBA) to detect insider threats. Which of the following activities would most likely trigger an alert for a compromised account?

⚠ Common exam trap

It's easy for candidates to confuse 'anomalous behavior' with 'malicious behavior,' but UBA specifically flags deviations from a baseline, and off-hours access is a textbook anomaly for a compromised account, whereas the other options represent normal or expected activities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User attempts to access a database at 2:00 AM, which is outside their normal pattern

User Behavior Analytics (UBA) establishes a baseline of normal user activity, including typical login times, locations, and access patterns. An attempt to access a database at 2:00 AM, which falls outside the user's established temporal baseline, represents a significant deviation that UBA algorithms flag as anomalous. This behavior is a classic indicator of a compromised account, as attackers often operate during off-hours to avoid detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User receives a large number of emails

    Why it's wrong here

    Receiving many emails is inbound activity the user does not initiate, and volume alone does not indicate account takeover. It tempts because email is a UBA-monitored channel, but the anomaly that flags compromise is outbound behaviour such as mass sending or unusual access, not receipt.

  • ✗

    User logs in from a recognized corporate device

    Why it's wrong here

    A recognised corporate device is a trusted, expected authentication context, so the risk score stays low and no alert triggers. It tempts because device identity feeds UBA risk scoring, but it is a legitimate signal; compromise alerts require deviation such as an unrecognised device or impossible travel.

  • ✓

    User attempts to access a database at 2:00 AM, which is outside their normal pattern

    Why this is correct

    UBA baselines each user's normal behaviour, so a 2:00 AM database access falling outside that learned pattern deviates from the established profile. This temporal anomaly is exactly the behavioural signal UBA is designed to flag for a potentially compromised account.

  • ✗

    User accesses the same files as usual during business hours

    Why it's wrong here

    Accessing the same files at the same times matches the established behavioural baseline, so no deviation is scored and no alert fires. It tempts because file access is a monitored UBA data source, but UBA flags anomalies; this activity is the normal pattern against which anomalies are measured.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst is reviewing logs from a SIEM and notices multiple failed login attempts for a privileged account from an IP address in a foreign country, followed by a successful login after hours. Which type of security monitoring tool would be most effective at detecting this pattern as anomalous behavior based on user baseline?

medium
  • A.Signature-based IDS
  • B.Network-based IPS
  • C.Host-based IDS
  • ✓ D.User Behavior Analytics (UBA)

Why D: User Behavior Analytics (UBA) is designed to establish a baseline of normal user activity and detect anomalies such as a privileged account logging in from an unusual geographic location after hours. Unlike signature or rule-based tools, UBA uses statistical modeling and machine learning to identify deviations from the user's historical patterns, making it ideal for detecting this type of credential misuse.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.