First Step in Creating an Anomaly Detection Process?
Which of the following is the first step to take when creating an anomaly detection process?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of the anomaly detection workflow, where candidates often mistakenly prioritize logging configuration over defining normal behavior first.
Anomaly detection relies on identifying deviations from established norms. This page confirms that building a baseline is the essential first step before selecting events or configuring logs.
Selecting logging options or creating an event log, as learners assume data collection must precede analysis without realizing the system needs a reference model to evaluate that data.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Establishing a baseline is the definitive first step because anomaly detection algorithms fundamentally rely on comparing real-time activity against a predefined model of normal behavior. Without this reference point, the system lacks the mathematical foundation to calculate deviation thresholds or distinguish between routine fluctuations and actual threats. CompTIA Security+ doctrine emphasizes that contextual normalization must precede all monitoring configurations to ensure accurate threat identification.Why the Other Options Are Wrong
Selecting events, choosing logging options, and creating event logs are implementation tasks that occur after the baseline is defined. Attempting to configure these components first results in unstructured data collection that cannot be meaningfully evaluated for anomalies. These steps are necessary for operationalizing the detection system, but they function as downstream dependencies rather than foundational prerequisites.Community Comment Notes
Learners consistently highlight that deviation identification is impossible without prior normalization, with one noting that "you have to have a baseline so something can stray away from what is normal". Others reinforce that defining expected traffic patterns establishes the necessary reference frame before any monitoring tools are deployed. The consensus correctly aligns with the technical requirement for historical performance modeling.Exam Strategy
When faced with process-order questions, always identify the foundational prerequisite before implementation steps. For monitoring concepts, look for options that establish context or normal states as the initial phase.
Frequently Asked Questions
Why isn't selecting logging options the first step?
Logging collects raw data, but without a baseline defining normal patterns, the collected logs lack context for deviation analysis.
How does a baseline affect threshold tuning?
Baselines provide statistical averages that directly inform alert thresholds, ensuring detections trigger only on genuine anomalies rather than routine spikes.