300-215 Question 159
Select 3You are a cybersecurity analyst monitoring threat intelligence feeds integrated into Cisco SecureX. One of the feeds reports a suspicious domain frequently communicating with an internal server. The domain has been flagged by multiple external sources for hosting malware, and further investigation reveals unusual login attempts and unexpected outbound data transfers from the internal server. Based on the threat intelligence feed and the observed activity, which Indicators of Compromise (IOCs) or Indicators of Attack (IOAs) should you prioritize for further investigation?
- A
The flagged suspicious domain communicating with the internal server
- B
The volume of outbound data transfers from the internal server
- C
The geolocation of the flagged domain's IP address
- D
The unusual login attempts detected on the internal server
- E
Historical threat intelligence reports about the domain's involvement in malware distribution
Show answer and explanation
Correct answers: A, B, D
Explanation
The flagged domain, unusual login attempts, and unexpected outbound data transfers are actionable IOCs and IOAs in this scenario. These indicators provide evidence of malicious activity or attack patterns that require immediate investigation to secure the internal assets. While context, such as geolocation or historical intelligence, is valuable, it does not directly contribute to identifying or responding to the active threat in this case.
- A. Correct.
The flagged suspicious domain is a critical IOC as it directly communicates with the internal server and has been reported for malicious activity.
- B. Correct.
The volume of outbound data transfers is an important IOA as it suggests potential data exfiltration, a common attacker behavior.
- C. Incorrect.
The geolocation of the flagged domain's IP address is useful context but not a direct IOC or IOA for prioritization in this scenario.
- D. Correct.
Unusual login attempts are a strong IOA that may indicate an active compromise or unauthorized access attempt.
- E. Incorrect.
Historical threat intelligence about the domain adds context but is less critical than current observed activity for prioritization.