
CompTIASecurityX (CASP+)
Domain 4Objective 1
Monitoring and Data Analysis CAS-005 Practice Questions (Page 6)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
22%of the exam
Questions 26–30
- 26
A SIEM alerts when network traffic deviates from the established baseline. What is the primary purpose of this baseline?
Select an answer first - 27
A security team wants to detect unusual network activity by establishing what is 'normal' for their environment. What should they create?
Select an answer first - 28
Which factor is MOST important when prioritizing security events in a SIEM?
Select an answer first - 29
A security analyst is investigating a potential data breach. The SIEM shows a successful login from an external IP, followed by a download of a large file from a file server, and then a connection to a known command-and-control (C2) server. What is the most likely attack chain?
Select an answer first - 30
A system administrator has a baseline for a web server that shows normal CPU usage is 30%. One day, the SIEM alerts that CPU usage is at 100% for 30 minutes. The administrator investigates and finds that a new web application is consuming excessive CPU. The application is critical to business operations. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.