AI Bot

Behavioral Analytics & Baseline Metrics Flashcards

CompTIA CySA+ CS0-004 (V4) Flashcards

Study our Behavioral Analytics & Baseline Metrics flashcards for the CompTIA CySA+ CS0-004 (V4) exam with 40+ flashcards. View as flashcards, a searchable table, or as a fun matching game.
CompTIA CySA+ CS0-004 (V4) Course Header Image
FrontBack
Difference between point anomaly and contextual anomalyPoint anomaly is an isolated outlier while contextual anomaly depends on context such as time or location
Explain moving average baselineBaseline computed as average of the most recent fixed window of observations
Explain seasonality adjustment in baseliningRemoving or modeling repeating patterns to prevent seasonal spikes from being flagged as anomalies
Explain z score for anomaly detectionZ score measures how many standard deviations a value is from the mean used to flag outliers
Give an example of a behavioral feature for UEBAAverage login time or number of distinct devices used by a user
How can PCA help in anomaly detectionPCA reduces dimensionality and highlights directions of unusual variance
How to interpret a high false positive rateModel or baseline may be too sensitive features may be noisy or thresholds misconfigured
How to measure operational impact of alertsTrack time to triage incident outcomes and analyst workload metrics
How to reduce alert fatigueTune thresholds add context and priority and implement feedback loops from analysts
How to use ensemble methods for anomaly detectionCombine multiple detectors and aggregate their scores for more robust alerts
How to validate a new baselineBacktest against historical incidents and measure detection and false positive rates
Name a behavioral metric for account compromise detectionUnusual geographic login or sudden increase in failed logins
Name a technique to reduce false positivesContext enrichment such as adding user role or device information
Name three types of baselines used in behavior analyticsStatic baseline rolling baseline and seasonal baseline
Name two statistical approaches for anomaly detectionDistribution based methods and time series decomposition
What is a baseline confidence intervalRange around baseline estimate that indicates expected variation used to set alert thresholds
What is a baseline in behavioral analyticsTypical normal pattern of activity defined from historical data used to detect deviations
What is a hybrid detection approachCombining statistical rules with machine learning models to leverage strengths of both
What is alert prioritizationRanking alerts by risk impact and confidence to focus analyst attention
What is an analyst feedback loopUsing analyst feedback to label alerts and retrain or recalibrate models
What is anomaly detectionProcess of identifying patterns that deviate significantly from expected behavior
What is collective anomalyGroup of data points that are anomalous together even if individual points are not
What is concept driftChange in the underlying data distribution over time that can invalidate a learned baseline or model
What is drift detection monitoringContinuously checking model performance and input distribution to detect when retraining is needed
What is EWMAExponentially Weighted Moving Average gives more weight to recent observations for quicker sensitivity to change
What is isolation forestTree based anomaly detection algorithm that isolates anomalies quickly by partitioning data
What is label leakage riskUsing features that indirectly encode the target leading to overoptimistic evaluation and poor generalization
What is precision in alertingProportion of alerts that are true positives
What is recall in alertingProportion of actual incidents that were detected by alerts
What is ROC AUC used for in anomaly detectionEvaluates trade off between true positive rate and false positive rate for a detector
What is the F1 scoreHarmonic mean of precision and recall used to balance both metrics
What is threshold hysteresisUsing separate thresholds for raising and clearing alerts to avoid flapping
What is unsupervised anomaly detectionDetecting anomalies without labeled data by modeling normal behavior only
What is user and entity behavior analytics UEBAAnalytics that model normal behavior of users and entities to detect insider threats and compromised accounts
What role does clustering play in UEBAGroups similar behavior profiles to find entities that deviate from their cluster
When to use supervised models for anomaly detectionWhen labeled examples of normal and anomalous behavior are available
When to use time series models for baseliningWhen data exhibits temporal dependencies trends or seasonality
Why is explainability important for behavioral alertsHelps analysts understand why an alert fired and speeds investigation
Why is feature engineering critical in behavioral analyticsGood features capture meaningful behavior and improve model accuracy and interpretability
Why tune thresholdsTo balance detection sensitivity against false positive rates and operational workload

About the Flashcards

Flashcards for the CompTIA CySA+ exam help students review behavioral analytics concepts used to identify unusual activity, model normal behavior, and detect security-relevant deviations. The deck covers baselines, concept drift, anomaly types, statistical scoring, time series methods, and seasonality adjustment.

These cards also reinforce how detection systems are evaluated and improved, including precision, recall, F1 score, ROC AUC, threshold tuning, and false positive reduction. Students can review UEBA, clustering, isolation forest, PCA, supervised and unsupervised models, alert prioritization, analyst feedback loops, explainability, and operational alert impact.

Topics covered in this flashcard deck:

  • Behavioral baselines
  • Anomaly detection
  • UEBA concepts
  • Detection metrics
  • Alert tuning
  • Model drift and validation
Share on...
Follow us on...