A threat intelligence analyst receives an indicator of compromise (IOC) consisting of an IP address associated with a known botnet C2. The IOC is 6 months old. What factor most affects the reliability of this IOC?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because IP-based IOCs are low-fidelity and short-lived; attackers frequently rotate IP addresses, making a 6-month-old IP IOC likely to produce false positives or miss current infrastructure. A is wrong because the number of associated threat actors does not directly affect the current validity of a specific IP address.
Full explanation below image
Full Explanation
B is correct because IP-based IOCs are low-fidelity and short-lived; attackers frequently rotate IP addresses, making a 6-month-old IP IOC likely to produce false positives or miss current infrastructure. A is wrong because the number of associated threat actors does not directly affect the current validity of a specific IP address. C is wrong because the format of IOC sharing (STIX/TAXII) improves automation but does not affect the validity of the underlying indicator. D is wrong because TLP classification controls who can share the IOC, not whether the indicator is still accurate.