Which two of the following statements about IOAs are true? (Choose two.)
- IOAs do not point to an attack that already happened; they point to an attack that might be taking place.
- IOAs do not point to an attack that is taking place; they analyze attacks that have already occurred.
- IOAs are a helpful resource for proactive threat mitigation but tend to generate more false positives than IOCs.
- IOAs are inappropriate for threat mitigation and do not produce the number of false positives that IOCs generate.
- One example of an IOA is an internal host running an application that uses well-known ports.
Explanation & Hint:
The two true statements about Indicators of Attack (IOAs) are:
The statement that IOAs analyze attacks that have already occurred is incorrect; that would be more indicative of Indicators of Compromise (IOCs). The statement about IOAs being inappropriate for threat mitigation is also not accurate; they are indeed useful for this purpose. Lastly, an example of an IOA would typically be more specific and behavior-based, such as unusual patterns of network traffic or unexpected changes in system configurations, rather than something as common as an internal host using well-known ports. |