CS0-003 · Question #84
A threat hurting team received a new loC from an ISAC that follows a threat actor's profile and activities. Which of the following should be updated NEXT?
The correct answer is D. The IDS signature. Examples of IoC: Unusual inbound and outbound network traffic Geographic irregularities, such as traffic from countries or locations where the organization does not have a presence Unknown applications within the system Unusual activity from administrator or privileged accounts,
Question
A threat hurting team received a new loC from an ISAC that follows a threat actor's profile and activities. Which of the following should be updated NEXT?
Options
- AThe whitelist
- BThe DNS
- CThe blocklist
- DThe IDS signature
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- C5% (2)
- D87% (33)
Explanation
Examples of IoC: Unusual inbound and outbound network traffic Geographic irregularities, such as traffic from countries or locations where the organization does not have a presence Unknown applications within the system Unusual activity from administrator or privileged accounts, including requests for additional An uptick in incorrect log-ins or access requests that may indicate brute force attacks Anomalous activity, such as an increase in database read volume Large numbers of requests for the same file Suspicious registry or system file changes Unusual Domain Name Servers (DNS) requests and registry configurations Unauthorized settings changes, including mobile device profiles Large amounts of compressed files or data bundles in incorrect or unexplained locations Analyst then create custom rules for specific organizational needs to find out whos doing these
Topics
Community Discussion
No community discussion yet for this question.