CompTIA SecurityX CAS-005 (V5) Practice Question

A security analyst is configuring a SIEM to help the operations team spot early indicators of compromise. The analyst wants the SIEM to raise alerts whenever server CPU utilization, user login times, or outbound network volume stray significantly from their normal patterns. Which of the following actions will BEST enable the SIEM to identify such anomalies quickly?

  • Implement geofencing rules to block traffic from high-risk countries.

  • Schedule quarterly vulnerability scans of all critical assets.

  • Document an incident-response runbook for common attack scenarios.

  • Build behavior baselines for systems, users, and network activity.

CompTIA SecurityX CAS-005 (V5)
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $64
$529.00 $465.00
SAVE $70
CompTIA SecurityX Voucher with Retake
v5 / CAS-005
Includes Retake
$578.00 $508.00
Bash, the Crucial Exams Chat Bot
AI Bot