ExamGecko
Question list
Search
Search

Related questions











Question 327 - 200-201 discussion

Report
Export

Which statement describes indicators of attack?

A.

internal hosts communicate with countries outside of the business range.

Answers
A.

internal hosts communicate with countries outside of the business range.

B.

Phishing attempts on an organization are blocked by mall AV.

Answers
B.

Phishing attempts on an organization are blocked by mall AV.

C.

Critical patches are missing.

Answers
C.

Critical patches are missing.

D.

A malicious file is detected by the AV software.

Answers
D.

A malicious file is detected by the AV software.

Suggested answer: A

Explanation:

Indicators of Attack (IoA) refer to observable behaviors or artifacts that suggest a security breach or ongoing attack.

When internal hosts communicate with countries outside the business range, it may indicate data exfiltration or command-and-control communication to an external threat actor.

Unlike Indicators of Compromise (IoC) which indicate that a system has already been compromised, IoAs are often used to identify malicious activity in its early stages.

Monitoring for unusual outbound connections is a crucial aspect of detecting advanced persistent threats (APTs) and other sophisticated attacks.

Difference Between Indicators of Compromise and Indicators of Attack

Cyber Threat Detection Using Indicators of Attack

Network Monitoring for Anomalous Behavior

asked 07/10/2024
Ruben Dallibor
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first