UEBA
User and Entity Behavior Analytics
Detects threats by flagging deviations from normal behavior baselines.
UEBA establishes baselines of normal activity for users and devices, then flags deviations such as impossible travel, unusual data access, or off hours logins that may signal compromise or insider threat. It relies on analytics and machine learning rather than fixed signatures, so it can surface novel behavior that rule based tools miss. It is often a component of SIEM or XDR platforms. The trade off is tuning effort, since loose baselines generate false positives.
User and Entity Behavior Analytics: baselines normal behavior and flags the weird ("is this account acting strange?").
Looking UEBA up is step one. Getting tested on it is step two.
A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.
Not affiliated with or endorsed by CompTIA.
