A SOC analyst is hunting for indicators of attack rather than indicators of compromise. Which telemetry pattern best supports an earlier-stage intrusion, such as reconnaissance or privilege escalation, before data is exfiltrated?
Select an answer to reveal the explanation.
Short Explanation
Think of it like watching someone try every door on a street: that's behavior, not a broken lock. You spot reconnaissance and privilege escalation before the house is robbed. The hash and beaconing are nice clues, but they show up after the intruder is already inside.
Full Explanation
Indicators of attack describe adversary behaviors and sequences, not just artifacts left behind. In this scenario, failed logons followed by SMB enumeration is an early behavioral pattern because it maps to reconnaissance, lateral movement, and possible privilege escalation while the attacker is still probing the environment. An EDR or SIEM can correlate authentication failures with network share discovery, making it actionable before data is stolen. A ransomware note is a post-compromise impact indicator; it confirms encryption occurred rather than warning of the intrusion path. Encrypted beaconing to a newly registered domain is strong evidence of command-and-control, but it usually follows initial execution and persistence. A SHA-256 hash found in quarantine is an indicator of compromise tied to a known file, useful for hunting but not a behavioral sequence showing pre-attack activity. Exam caveat: CS0-004 rewards distinguishing behavioral indicators of attack from static indicators of compromise and from post-impact artifacts. Operational check: correlate authentication failures with SMB, RPC, or LDAP enumeration events across hosts and escalate when the same account or source shows probing followed by unusual privilege use.