nerdexam
CompTIA

CAS-005 · Question #71

Which of the following is the security engineer most likely doing?

The correct answer is A. Assessing log in activities using geolocation to tune impossible Travel rate alerts. In the given scenario, the security engineer is likely examining login activities and their associated geolocations. This type of analysis is aimed at identifying unusual login patterns that might indicate an impossible travel scenario. An impossible travel scenario is when a…

Submitted by anjalisingh· Mar 6, 2026Security Operations

Question

Which of the following is the security engineer most likely doing?

Exhibits

CAS-005 question #71 exhibit 1
CAS-005 question #71 exhibit 2

Options

  • AAssessing log in activities using geolocation to tune impossible Travel rate alerts
  • BReporting on remote log-in activities to track team metrics
  • CThreat hunting for suspicious activity from an insider threat
  • DBaselining user behavior to support advanced analytics

How the community answered

(43 responses)
  • A
    77% (33)
  • B
    7% (3)
  • C
    2% (1)
  • D
    14% (6)

Explanation

In the given scenario, the security engineer is likely examining login activities and their associated geolocations. This type of analysis is aimed at identifying unusual login patterns that might indicate an impossible travel scenario. An impossible travel scenario is when a single user account logs in from geographically distant locations in a short time, which is physically impossible. By assessing login activities using geolocation, the engineer can tune alerts to identify and respond to potential security breaches more effectively.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice