Quiz 4 Question 5 of 20

Your enterprise SOC monitors on-prem AD, IaaS workloads, EDR, SIEM, SOAR, and a threat-intel feed. A feed reports that a ransomware group has obtained valid cloud identity tokens and can create service principals, but no malicious sign-ins or role changes are logged yet. Which type of threat intelligence indicator best supports assessing what the adversary may be able to do before compromise is observed?

Select an answer to reveal the explanation.

Motivation