CompTIA Security+ (SY0-701)Security OperationsHard
A SOC analyst configures a monitoring platform to build a baseline of typical login times, data access volume, and file transfer patterns for each employee. When a user account suddenly downloads ten times its normal data volume at 3 a.m. from an unusual location, the platform generates a high-risk alert even though no signature-based rule was triggered. Which technology enables this capability?
- AData loss prevention (DLP)
- BEndpoint detection and response (EDR)
- CUser and entity behavior analytics (UEBA)
- DSecurity orchestration, automation, and response (SOAR)
Show answer & explanationAnswer & explanation
Correct answer: C. User and entity behavior analytics (UEBA)
UEBA uses machine learning to establish behavioral baselines for users and entities, then flags statistically anomalous activity (like unusual volume, time, or location) even without a matching signature. DLP focuses on content inspection to block sensitive data leaving the network, EDR focuses on endpoint process/telemetry analysis, and SOAR automates response actions rather than detecting behavioral anomalies.
Why the other options are wrong
- A. DLP inspects content for sensitive data patterns, not behavioral baselining.
- B. EDR monitors endpoint activity/processes, not organization-wide behavioral baselines.
- D. SOAR automates and orchestrates response workflows, it doesn't perform behavior baselining itself.
User and Entity Behavior Analytics (UEBA)
A security analytics approach that establishes baselines of normal user/entity behavior and detects anomalies that may indicate compromise or insider threats.
- Uses machine learning/statistical modeling
- Detects anomalies without relying on known signatures
- Often integrated into SIEM platforms
Memory trick: UEBA is a nosy neighbor who notices when you leave the house at an unusual hour.