CompTIA Security+ (SY0-701)Security OperationsMedium
A security analyst is investigating a suspected data exfiltration event. The analyst discovers a specific IP address that was observed making unusually large outbound connections to an external server, followed by a sudden drop in network traffic from the internal host. The analyst then uses this IP address to search logs across the SIEM, firewall, and proxy servers to find other related activities. What type of information does this IP address represent in the context of a security investigation?
- AExploit
- BThreat Actor
- CVulnerability
- DIndicator of Compromise (IOC)
Show answer & explanationAnswer & explanation
Correct answer: D. Indicator of Compromise (IOC)
An Indicator of Compromise (IOC) is a piece of forensic data, such as an IP address, domain name, or file hash, that identifies malicious activity on a network or system. The discovered IP address, linked to suspicious outbound traffic, serves as an IOC for further investigation.
Why the other options are wrong
- A. An exploit is the specific code or technique used to take advantage of a vulnerability; the IP address is an artifact of the attack, not the exploit itself.
- B. A threat actor is the individual or group performing the attack; the IP address is a tool or artifact used by the actor, not the actor themselves.
- C. A vulnerability is a weakness in a system; the IP address is evidence of an attack, not the weakness itself.
Indicator of Compromise (IOC)
A piece of forensic data found on a network or operating system that indicates a potential intrusion or malicious activity.
- Specific, observable artifact of an attack.
- Examples include malicious IP addresses, domains, file hashes, registry keys.
- Used to detect, investigate, and prevent future attacks.
Memory trick: An 'IOC' is an 'Individual Observable Clue' of a breach.