CompTIA Security+ (SY0-701)Security OperationsEasy

A security analyst is investigating a suspected data exfiltration event. The analyst discovers a large volume of unusual outbound traffic to an unknown IP address, accompanied by several failed login attempts from an internal server to an external host. Which of the following best describes these findings?

  1. AIndicators of Compromise (IOCs)
  2. BRisk indicators
  3. CSecurity baselines
  4. DThreat intelligence feeds
Show answer & explanation

Correct answer: A. Indicators of Compromise (IOCs)

Indicators of Compromise (IOCs) are forensic artifacts found on a network or operating system that indicate a high probability of intrusion. The observed unusual outbound traffic and failed login attempts are classic examples of IOCs.

Why the other options are wrong

  • B. Risk indicators point to potential vulnerabilities or threats but are not direct evidence of an attack.
  • C. Security baselines define normal system behavior, deviations from which might indicate an anomaly, but are not the findings themselves.
  • D. Threat intelligence feeds provide information about known threats, but the observed findings are actual internal events, not external feeds.

Indicator of Compromise (IOC)

Forensic data found on a network or operating system that indicates a high probability of intrusion or a successful security breach.

  • Evidence of an attack, not just a potential threat.
  • Can include malicious file hashes, IP addresses, domain names, unusual network traffic, or abnormal system behavior.
  • Used to detect, prevent, and respond to cyberattacks.

Memory trick: IOCs are the 'clues' left behind by an intruder.

More Security Operations questions