SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium

A security incident response team receives an alert indicating unusually high outbound network traffic from an internal server, destined for a known malicious IP address. Upon further investigation, they discover that multiple files have been encrypted on the server. Which of the following threat intelligence indicators is most relevant to understanding this specific incident?

  1. AVulnerabilities
  2. BThreat Actors
  3. CTactics, Techniques, and Procedures (TTPs)
  4. DIndicators of Compromise (IoCs)
Show answer & explanation

Correct answer: D. Indicators of Compromise (IoCs)

Indicators of Compromise (IoCs) are forensic artifacts found on a network or operating system that indicate a computer intrusion. The malicious IP, encrypted files, and high outbound traffic are all direct IoCs of the ongoing incident.

Why the other options are wrong

  • A. Vulnerabilities are weaknesses that can be exploited, not the evidence of an exploit occurring.
  • B. Threat actors are the individuals or groups behind the attack, not the technical evidence of it.
  • C. TTPs describe how threat actors operate, not specific artifacts of a breach itself.

Indicators of Compromise (IoCs)

Forensic data found on a network or operating system that indicates a computer intrusion or malicious activity.

  • Examples include malicious IP addresses, domain names, file hashes, registry keys, and unusual traffic patterns.
  • Used to detect, identify, and prevent future attacks.
  • Often shared within the cybersecurity community to enhance defenses.

Memory trick: IoCs are the 'clues' left behind at the crime scene.

More Risk Identification, Monitoring, and Analysis questions