What is an Indicator of Compromise (IOC) and give two examples.

Study for the Cybercrime Test. Use flashcards and multiple choice questions, each with hints and explanations, to prepare for your exam! Master cybercrime prevention and stay ahead of threats.

Multiple Choice

What is an Indicator of Compromise (IOC) and give two examples.

Explanation:
An Indicator of Compromise is evidence that suggests a security breach has occurred, serving as artifacts that help detect or investigate intrusions. Two common examples are a known attacker IP address appearing in logs and a file hash that matches a malware sample. These indicators point to malicious activity and help responders trace what happened and where it affected systems. The other items are not IOCs: routine software updates and changelogs reflect maintenance activity, not signs of compromise; password policies and login attempt limits are protective controls; and firewall rules or access control lists are defensive configurations, not evidence that a breach occurred.

An Indicator of Compromise is evidence that suggests a security breach has occurred, serving as artifacts that help detect or investigate intrusions. Two common examples are a known attacker IP address appearing in logs and a file hash that matches a malware sample. These indicators point to malicious activity and help responders trace what happened and where it affected systems. The other items are not IOCs: routine software updates and changelogs reflect maintenance activity, not signs of compromise; password policies and login attempt limits are protective controls; and firewall rules or access control lists are defensive configurations, not evidence that a breach occurred.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy