700-270 · Question #37
A file-type embedded attack is an example of which loC event category?
The correct answer is A. security intelligence. Security Intelligence is correct because file-type embedded attacks - where malicious payloads are hidden within legitimate-seeming file formats (like PDFs or images) - are detected and categorized using threat intelligence feeds that identify known malicious file characteristics
Question
A file-type embedded attack is an example of which loC event category?
Options
- Asecurity intelligence
- BIPS
- Cmalware
- Dfirewall
How the community answered
(23 responses)- A91% (21)
- B4% (1)
- D4% (1)
Explanation
Security Intelligence is correct because file-type embedded attacks - where malicious payloads are hidden within legitimate-seeming file formats (like PDFs or images) - are detected and categorized using threat intelligence feeds that identify known malicious file characteristics, making them an intelligence-driven IoC event.
Why the distractors are wrong:
- B (IPS): IPS events are triggered by signature/anomaly-based detection of network-level intrusion attempts, not file-type embedding techniques.
- C (Malware): While embedded files deliver malware, the IoC event category for the attack method (embedding within a file type) maps to security intelligence, not the general malware category.
- D (Firewall): Firewall events relate to access control decisions based on traffic rules/policies, not file content analysis.
Memory tip: Think of Security Intelligence as "knowing the enemy's disguise" - if an attack hides inside something that looks normal (a file type), you need intelligence to recognize it, not just a wall or a signature rule.
Topics
Community Discussion
No community discussion yet for this question.