Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 2 Question 98 Discussion

Which statement describes indicators of attack?
A) internal hosts communicate with countries outside of the business range.
B) Phishing attempts on an organization are blocked by mall AV.
C) Critical patches are missing.
D) A malicious file is detected by the AV software.

Cisco 200-201 Exam - Topic 2 Question 98 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 98
Topic #: 2
[All 200-201 Questions]

Which statement describes indicators of attack?

Show Suggested Answer Hide Answer
Suggested Answer: A

Indicators of Attack (IoA) refer to observable behaviors or artifacts that suggest a security breach or ongoing attack.

When internal hosts communicate with countries outside the business range, it may indicate data exfiltration or command-and-control communication to an external threat actor.

Unlike Indicators of Compromise (IoC) which indicate that a system has already been compromised, IoAs are often used to identify malicious activity in its early stages.

Monitoring for unusual outbound connections is a crucial aspect of detecting advanced persistent threats (APTs) and other sophisticated attacks.


Difference Between Indicators of Compromise and Indicators of Attack

Cyber Threat Detection Using Indicators of Attack

Network Monitoring for Anomalous Behavior

Contribute your Thoughts:

0/2000 characters
Hollis
9 months ago
B seems off, AV isn't always reliable against phishing.
upvoted 0 times
...
Mickie
9 months ago
D is a clear indicator of an attack, no doubt about it!
upvoted 0 times
...
Glennis
10 months ago
Wait, are we really saying mall AV can block phishing? Sounds sketchy.
upvoted 0 times
...
Carlton
10 months ago
I think C is more concerning. Missing patches can lead to serious vulnerabilities.
upvoted 0 times
...
Lynette
10 months ago
A is definitely a red flag!
upvoted 0 times
...
Selene
10 months ago
I feel like B is more about prevention than an actual indicator of an attack. It’s confusing how they frame it in the question.
upvoted 0 times
...
Farrah
11 months ago
D seems like a clear indicator since detecting a malicious file usually means something is wrong, but I wonder if it’s the most critical one.
upvoted 0 times
...
Julio
11 months ago
I remember a practice question where missing patches were highlighted as a vulnerability. So, C could be a strong indicator too.
upvoted 0 times
...
Hillary
11 months ago
I think option A might be a sign of an attack, but I'm not entirely sure if it's the best indicator.
upvoted 0 times
...
Louis
11 months ago
I'm a bit confused by this question. Are we looking for the single best indicator, or just any potential signs of an attack? I want to make sure I understand the question properly before selecting an answer.
upvoted 0 times
...
Rex
11 months ago
Hmm, this is a tricky one. I'm not entirely sure what the best answer is here. I'll need to think through the different options and see which one seems to best describe common attack indicators.
upvoted 0 times
...
Yuette
11 months ago
This seems like a straightforward question about indicators of potential attacks. I'll carefully review each option and think about the key signs of malicious activity.
upvoted 0 times
...
Loren
11 months ago
Okay, I've got this. Internal hosts communicating outside the normal business range is a classic sign of potential compromise. That's got to be the right answer here.
upvoted 0 times
...
Torie
2 years ago
Haha, you guys are all over the place! I'm just gonna go with D and call it a day. Malicious file detected? That's like a giant neon sign saying 'You've been hacked!'
upvoted 0 times
...
Vi
2 years ago
Aw man, this question is giving me a headache. I'm just going to go with the one that sounds the most tech-savvy. C it is! Missing patches, that's got to be the one.
upvoted 0 times
...
Elliot
2 years ago
Wait, wait, wait. You're all missing the obvious choice here. It's clearly C - missing critical patches. That's just asking for trouble! Step up that cybersecurity game, people.
upvoted 0 times
Anisha
2 years ago
C) Critical patches are missing.
upvoted 0 times
...
Flo
2 years ago
B) Phishing attempts on an organization are blocked by mall AV.
upvoted 0 times
...
Lemuel
2 years ago
A) internal hosts communicate with countries outside of the business range.
upvoted 0 times
...
...
Michal
2 years ago
I don't know about you guys, but I'm going with option B. Phishing attempts getting blocked by the AV software? That's a good thing, right? Gotta protect that organization from those scammers!
upvoted 0 times
...
Anika
2 years ago
Ooh, this is a tough one. I'm torn between C and D, but I think I'll go with D. Detecting a malicious file is a pretty clear sign of an attack, don't you think?
upvoted 0 times
Deangelo
2 years ago
Yeah, but I believe detecting a malicious file is a more direct indicator.
upvoted 0 times
...
Dudley
2 years ago
I think missing critical patches could also be a sign of an attack.
upvoted 0 times
...
Tasia
2 years ago
I agree, detecting a malicious file is a strong indicator of an attack.
upvoted 0 times
...
...
Jina
2 years ago
But what about option C) Critical patches are missing? That could also be a sign of an attack, right?
upvoted 0 times
...
Toshia
2 years ago
Hmm, I'm not sure. I think option A might be the way to go - internal hosts communicating with countries outside the business range seems like a red flag to me.
upvoted 0 times
Ayesha
2 years ago
True, both options A and D could indicate a potential security breach. It's important to stay vigilant.
upvoted 0 times
...
Alton
2 years ago
But what about option D? A malicious file being detected by the AV software could also be a sign of an attack.
upvoted 0 times
...
Rashida
2 years ago
I agree, option A does seem like a potential indicator of attack.
upvoted 0 times
...
...
Oliva
2 years ago
I think option C is the best answer here. Missing critical patches can definitely be an indicator of potential attack.
upvoted 0 times
Millie
2 years ago
A malicious file being detected by the AV software is also a clear sign of an attack.
upvoted 0 times
...
Portia
2 years ago
True, that could indicate unauthorized access or data exfiltration.
upvoted 0 times
...
Abraham
2 years ago
But what about when internal hosts communicate with countries outside of the business range? That could also be a red flag.
upvoted 0 times
...
Ernie
2 years ago
I agree, missing critical patches can leave vulnerabilities for attackers to exploit.
upvoted 0 times
...
...
Tasia
2 years ago
I agree with King, because detecting a malicious file is a clear indicator of an attack.
upvoted 0 times
...
King
2 years ago
I think the answer is D) A malicious file is detected by the AV software.
upvoted 0 times
...

Save Cancel