A threat-intel feed gives your SOC a list of file hashes and C2 IP addresses from a phishing campaign observed three months ago. Which limitation makes these indicators least reliable for detecting new malicious activity?
Select an answer to reveal the explanation.
Short Explanation
Think of IOCs like license plates: great for catching a car you already saw, useless if the bad guy changes plates tomorrow. Your feed from three months ago may match known malware, but attackers rotate IPs, domains, and hashes fast. Don't confuse a stale indicator with a durable detection.
Full Explanation
Indicators of compromise such as file hashes, IPs, and domains are tactical and perishable. Attackers rotate infrastructure, recompile payloads, change filenames, and use disposable domains or cloud services, so an older IOC may stop matching as the adversary adapts. Effective detection pairs IOC matching with behavioral hunting, such as anomalous parent-child processes, unusual network flows, persistence mechanisms, or Sigma rules mapped to MITRE ATT&CK techniques. A limitation described as forensic-only is inaccurate because modern SIEMs and SOAR platforms routinely ingest and normalize IOC feeds for alert enrichment and correlation. A claim of complete zero-day coverage is incorrect because hashes and network artifacts are not general behavioral models and cannot reliably identify novel malware that has not been observed. The idea that privileged decryption is required is wrong because IOC matching usually occurs against already-collected metadata and telemetry, such as NetFlow, proxy logs, EDR process telemetry, or file hashes, without decrypting C2 payloads. Exam caveat: the question tests the lifecycle limitation of IOC-based detection, not enrichment tooling or encrypted traffic analysis. Operational check: measure IOC hit rates over time and retire or tune indicators that generate no matches while hunting for stable TTPs that persist across campaigns.