CompTIA CAS-005 Question Answer
A threat hunter is identifying potentially malicious activity associated with an APT. When the threat hunter runs queries against the SIEM platform with a date range of 60 to 90 days ago, the involved account seems to be typically most active in the evenings. When the threat hunter reruns the same query with a date range of 5 to 30 days ago, the account appears to be most active in the early morning. Which of the following techniques is the threat hunter using to better understand the data?
CompTIA CAS-005 Summary
- Vendor: CompTIA
- Product: CAS-005
- Update on: Dec 8, 2025
- Questions: 326

