Q42Security Concepts
What distinguishes an indicator of attack (IoA) from indicators of compromise (IoC)?
← → navigate · a answer
Community votes
Discussion · 7
D 4
Selected Answer: D
IoC = Evidence that an attack already happened.
IoA = Indicators an attack will or can happen.
IoA
Digital or physical evidence of a cyberattacker's intent to attack. IOA detection focuses specifically on an adversary's motive rather than the specific tools or methods used.
https://www.strongdm.com/what-is/indicator-of-attack-ioa-security#:~:text=An%20indicator%20of%20attack%20(IOA,specific%20tools%20or%20methods%20used.
3
Answer: D This is correct because an Indicator of Compromise (IoC) is a sign that a system or network has already been compromised, and is used to tell whether an attack has already happened and to identify the scope of the compromise. An Indicator of Attack (IoA), on the other hand, is a signal or pattern that suggests an attack is currently underway or about to happen, and is used to detect and respond to an attack in progress.
D 3
Selected Answer: D
the answer is D
This is correct because an Indicator of Compromise (IoC) is a sign that a system or network has already been compromised, and is used to determine whether an attack has already happened and to identify the scope of the compromise. An Indicator of Attack (IoA), on the other hand, is a signal or pattern suggesting that an attack is currently underway or about to occur, and is used to detect and respond to an attack in progress.
2
D is the correct answer.
2
Fo me, D is right. I think that IoC is the evidence that a security breach has happened.
and IoA helps prepare for future attack methods.
D 2
Selected Answer: D
IOCs are artifacts that point to a system having been breached, while IOAs are behavior patterns that show an attack is underway
B 1
Selected Answer: B
I think clearly B --> IoA is the evidence that a security breach has happened, and IoC lets organizations act before the vulnerability can be exploited