
CompTIASecurityX (CASP+)
Domain 4Objective 1
Monitoring and Data Analysis CAS-005 Practice Questions (Page 4)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
22%of the exam
Questions 16–20
- 16
A security analyst is reviewing a raw SIEM event and needs to extract the source IP address, destination port, and event category from the log entry. Which SIEM feature is specifically designed for this task?
Select an answer first - 17
Which of the following is an example of a system behavior baseline metric?
Select an answer first - 18
A SIEM receives a log entry in the following format: "src=192.168.1.10 dst=10.0.0.5 sport=12345 dport=443 proto=tcp". Which SIEM capability would allow an analyst to query for all events where dport=443?
Select an answer first - 19
A user behavior baseline for an employee shows that they typically log in from 9 AM to 5 PM, access a specific set of file shares, and use a standard workstation. One day, the SIEM alerts that the user logged in at 2 AM from a remote IP address and accessed sensitive HR files. The user is on vacation. What is the most likely conclusion?
Select an answer first - 20
An analyst wants to identify all security events that originated from the same source IP address within a 10-minute window. Which SIEM feature is most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.