Quiz 4 Question 3 of 20

A threat-intel feed gives your SOC a list of file hashes and C2 IP addresses from a phishing campaign observed three months ago. Which limitation makes these indicators least reliable for detecting new malicious activity?

Select an answer to reveal the explanation.

Motivation