First Step in Creating an Anomaly Detection Process?

Answer Correct answer: B — Building a baseline establishes the normal behavior reference point required before any anomaly detection process can identify deviations.

Which of the following is the first step to take when creating an anomaly detection process?

  1. Selecting events
  2. Building a baseline Correct Answer
  3. Selecting logging options
  4. Creating an event log

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of the anomaly detection workflow, where candidates often mistakenly prioritize logging configuration over defining normal behavior first.

Anomaly detection relies on identifying deviations from established norms. This page confirms that building a baseline is the essential first step before selecting events or configuring logs.

Selecting logging options or creating an event log, as learners assume data collection must precede analysis without realizing the system needs a reference model to evaluate that data.

Community Discussion (5 comments)

LayinCable 👍 3 Selected: B
In order to experience an anomaly, you have to have a baseline so something can stray away from what is normal which then makes: An "anomaly"
shady23 👍 1 Selected: B
B. Building a baseline
salah112 👍 2 Selected: B
B. Building a baseline The first step in creating an anomaly detection process is typically building a baseline. A baseline is a reference point that represents normal behavior within a system or network. By establishing what is considered normal, it becomes possible to identify deviations or anomalies when they occur.
7308365 👍 1
B. Building a baseline Defining what baseline "normal" traffic or events are is the first step to creating an anomaly detection process
Hs1208 👍 3 Selected: B
The first step in anomaly detection is to establish a baseline of normal behavior.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Establishing a baseline is the definitive first step because anomaly detection algorithms fundamentally rely on comparing real-time activity against a predefined model of normal behavior. Without this reference point, the system lacks the mathematical foundation to calculate deviation thresholds or distinguish between routine fluctuations and actual threats. CompTIA Security+ doctrine emphasizes that contextual normalization must precede all monitoring configurations to ensure accurate threat identification.

Why the Other Options Are Wrong

Selecting events, choosing logging options, and creating event logs are implementation tasks that occur after the baseline is defined. Attempting to configure these components first results in unstructured data collection that cannot be meaningfully evaluated for anomalies. These steps are necessary for operationalizing the detection system, but they function as downstream dependencies rather than foundational prerequisites.

Community Comment Notes

Learners consistently highlight that deviation identification is impossible without prior normalization, with one noting that "you have to have a baseline so something can stray away from what is normal". Others reinforce that defining expected traffic patterns establishes the necessary reference frame before any monitoring tools are deployed. The consensus correctly aligns with the technical requirement for historical performance modeling.

Exam Strategy

When faced with process-order questions, always identify the foundational prerequisite before implementation steps. For monitoring concepts, look for options that establish context or normal states as the initial phase.

Frequently Asked Questions

Why isn't selecting logging options the first step?

Logging collects raw data, but without a baseline defining normal patterns, the collected logs lack context for deviation analysis.

How does a baseline affect threshold tuning?

Baselines provide statistical averages that directly inform alert thresholds, ensuring detections trigger only on genuine anomalies rather than routine spikes.

Related Analysis

← Back to SY0-601 Study Guide