nerdexam
Cisco

350-201(NEW-127Q) · Question #36

Refer to the exhibit. Which two Indicators of Attack are present on this alert? (Choose two.)

The correct answer is A. lateral movement. Lateral movement (A) is correct because it describes attacker behavior and intent - moving through a network after initial access - which is the defining characteristic of an Indicator of Attack (IoA). IoAs focus on what attackers are doing, not just artifacts left behind. An…

Threat Detection and Response

Question

Refer to the exhibit. Which two Indicators of Attack are present on this alert? (Choose two.)

Options

  • Alateral movement
  • Bregistry modification
  • Cunexpected, compressed archive file parent
  • Dsuspicious system file changes

How the community answered

(23 responses)
  • A
    78% (18)
  • B
    4% (1)
  • C
    13% (3)
  • D
    4% (1)

Explanation

Lateral movement (A) is correct because it describes attacker behavior and intent - moving through a network after initial access - which is the defining characteristic of an Indicator of Attack (IoA). IoAs focus on what attackers are doing, not just artifacts left behind. An alert showing process execution or authentication patterns consistent with network traversal directly signals an active attack in progress.

Unexpected, compressed archive file parent (C) is also correct (the second answer the question requires). A compressed archive spawning child processes (e.g., zip.exe launching cmd.exe) is a classic IoA behavioral pattern - it signals an attacker delivering and executing a payload, not just a static artifact.

Why the distractors are wrong:

  • B (registry modification) - registry changes are typically an Indicator of Compromise (IoC), a forensic artifact of what happened, not necessarily a real-time behavioral signal of an ongoing attack.
  • D (suspicious system file changes) - similarly an IoC; it tells you something happened after the fact, not the attacker's live intent or method.

Memory tip: Think of IoAs as a security camera (catching behavior in real time - lateral movement, suspicious parent/child processes) versus IoCs as fingerprints (artifacts discovered after the fact - registry keys, file changes). If it describes attacker behavior or technique in motion, it's an IoA.

Topics

#Indicators of Attack#Lateral Movement#Threat Detection#Alert Analysis

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice