nerdexam
CompTIA

CS0-003 · Question #84

A threat hurting team received a new loC from an ISAC that follows a threat actor's profile and activities. Which of the following should be updated NEXT?

The correct answer is D. The IDS signature. Examples of IoC: Unusual inbound and outbound network traffic Geographic irregularities, such as traffic from countries or locations where the organization does not have a presence Unknown applications within the system Unusual activity from administrator or privileged accounts,

Submitted by yousef_jo· Mar 6, 2026Security operations

Question

A threat hurting team received a new loC from an ISAC that follows a threat actor's profile and activities. Which of the following should be updated NEXT?

Options

  • AThe whitelist
  • BThe DNS
  • CThe blocklist
  • DThe IDS signature

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    5% (2)
  • D
    87% (33)

Explanation

Examples of IoC: Unusual inbound and outbound network traffic Geographic irregularities, such as traffic from countries or locations where the organization does not have a presence Unknown applications within the system Unusual activity from administrator or privileged accounts, including requests for additional An uptick in incorrect log-ins or access requests that may indicate brute force attacks Anomalous activity, such as an increase in database read volume Large numbers of requests for the same file Suspicious registry or system file changes Unusual Domain Name Servers (DNS) requests and registry configurations Unauthorized settings changes, including mobile device profiles Large amounts of compressed files or data bundles in incorrect or unexplained locations Analyst then create custom rules for specific organizational needs to find out whos doing these

Topics

#Threat intelligence#IoC#IDS/IPS signatures#Security operations

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice