SSCP Risk Identification, Monitoring, and Analysis Practice Question
Which of the following is a key advantage of using a behavior-based detection approach in a User and Entity Behavior Analytics (UEBA) system?
⚠ Common exam trap
A common mix-up: candidates assume behavior-based detection is easier or produces fewer false positives, but the exam emphasizes that its key advantage is detecting unknown threats, not operational simplicity or accuracy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ability to detect previously unknown threats based on anomalous behavior
Behavior-based detection in UEBA establishes a baseline of normal user and entity activity using machine learning and statistical models. It then identifies deviations from this baseline, enabling the detection of novel or previously unknown threats, such as zero-day exploits or insider threats, without relying on pre-defined signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ability to detect previously unknown threats based on anomalous behavior
Why this is correct
Behaviour-based detection builds baselines of normal user and entity activity, so deviations trigger alerts without relying on known signatures. This satisfies the stem's requirement for identifying previously unknown threats, catching novel attack patterns or compromised accounts whose activity has never been catalogued.
- ✗
Requires less data processing than signature-based detection
Why it's wrong here
UEBA consumes vast telemetry volumes to build behavioural baselines, so it demands more data processing, not less. Signature-based detection compares events against fixed patterns and needs comparatively little. The appeal is that behaviour analysis sounds lightweight, but correlation across users, entities and time is computationally heavier.
- ✗
Easier to configure and maintain
Why it's wrong here
Behaviour-based UEBA requires baselining normal activity per user and entity, so tuning thresholds and suppressing false positives is ongoing work, not a configuration advantage. It is tempting because signature or rule-based tools are configured once, but those cannot detect novel insider drift, which is what UEBA exists to catch.
- ✗
Lower false positive rates compared to signature-based detection
Why it's wrong here
Behaviour-based UEBA detects deviations from learned baselines, which surfaces novel activity signatures miss, but it also generates false positives from legitimate unusual behaviour, so lower false positive rates are not its advantage. Signature-based detection is tempting to contrast here, yet signatures excel at known-threat precision, not UEBA.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.