XSIAM-ANALYST · Question #28
In the Identity Threat Detection and Response (ITDR) module, what does "compromised identity" typically indicate?
The correct answer is B. Unauthorized access or behavior from a known identity. Compromised identity in ITDR refers to unauthorized access or anomalous behavior originating from a legitimate, known user account - meaning an attacker has hijacked valid credentials to operate as that user (option B). ITDR systems specifically monitor identity-based signals…
Question
In the Identity Threat Detection and Response (ITDR) module, what does "compromised identity" typically indicate?
Options
- AFailed software update
- BUnauthorized access or behavior from a known identity
- CMissing antivirus signature
- DUSB device connection
How the community answered
(24 responses)- A4% (1)
- B92% (22)
- C4% (1)
Explanation
Compromised identity in ITDR refers to unauthorized access or anomalous behavior originating from a legitimate, known user account - meaning an attacker has hijacked valid credentials to operate as that user (option B). ITDR systems specifically monitor identity-based signals like impossible travel, privilege escalation, or off-hours logins to detect this pattern.
Options A, C, and D are wrong because they describe endpoint or device security concerns (software updates, antivirus signatures, USB connections), which fall under EDR (Endpoint Detection and Response) or traditional security tools - not identity-focused detection. ITDR is narrowly scoped to identity planes: credentials, accounts, and access behavior.
Memory tip: Think of ITDR as "who is acting, not what is running." If the threat involves an account doing something suspicious, it's ITDR. If it involves a device or software doing something suspicious, it's EDR.
Topics
Community Discussion
No community discussion yet for this question.