Your enterprise SOC monitors on-prem AD, IaaS workloads, EDR, SIEM, SOAR, and a threat-intel feed. A feed reports that a ransomware group has obtained valid cloud identity tokens and can create service principals, but no malicious sign-ins or role changes are logged yet. Which type of threat intelligence indicator best supports assessing what the adversary may be able to do before compromise is observed?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a burglar's toolkit: seeing a crowbar doesn't prove they robbed you, but it tells you what they could do. Capability indicators answer 'could they do this?' not 'did they do this?' The trap is confusing them with intent, infrastructure, or actual compromise evidence.
Full Explanation
Capability indicators describe what an adversary is able to do based on access, tools, skills, or techniques, even when no breach has been observed. In a hybrid estate, a report that a group can use stolen OAuth tokens to create service principals tells an analyst to consider identity and cloud control-plane impact, then hunt for the conditions that would make that possible. Intent indicators describe what an adversary wants to achieve or why a target was selected, so they do not establish ability. Infrastructure indicators describe adversary-owned or adversary-used network assets such as domains, hosting, or proxies, which helps attribution and blocking but not potential action against your environment. Compromise indicators are artifacts showing unauthorized activity has already occurred, such as suspicious sign-ins or malicious process execution, so they confirm breach rather than forecast capability. Exam caveat: CS0-004 expects you to separate potential from observed: capability answers could they do this, intent answers what do they want, infrastructure answers where are they operating, and compromise indicators answer has it happened. Operational check: map the capability claim to relevant TTPs, then review identity, cloud audit, and endpoint telemetry for token abuse, privilege changes, and anomalous administrative actions.