internal hosts communicate with countries outside of the business range.
B.
Phishing attempts on an organization are blocked by mall AV.
C.
Critical patches are missing.
D.
A malicious file is detected by the AV software.
The Answer Is:
A
This question includes an explanation.
Explanation:
Indicators of Attack (IoA) refer to observable behaviors or artifacts that suggest a security breach or ongoing attack.
When internal hosts communicate with countries outside the business range, it may indicate data exfiltration or command-and-control communication to an external threat actor.
Unlike Indicators of Compromise (IoC) which indicate that a system has already been compromised, IoAs are often used to identify malicious activity in its early stages.
Monitoring for unusual outbound connections is a crucial aspect of detecting advanced persistent threats (APTs) and other sophisticated attacks.
References
Difference Between Indicators of Compromise and Indicators of Attack
Cyber Threat Detection Using Indicators of Attack
Network Monitoring for Anomalous Behavior
200-201 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"