ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During a quarterly risk review, a security analyst must update the organization's risk register with newly discovered indicators of compromise (IOCs). From recent monitoring data, the analyst notes the following observations. Which observation is an IOC that should be entered into the register?
A documented server hardening baseline stating that all Windows servers must have SMBv1 disabled
Daily backup jobs creating successful completion entries in the enterprise backup logs
Multiple external IP addresses sequentially probing TCP port 22 on the company's firewall over a ten-minute window
A SHA-256 hash on a workstation executable that exactly matches a malware signature published by a trusted threat-intelligence feed
An indicator of compromise is a concrete artifact showing that a system is or was likely breached. File hashes that match known malware signatures are classic IOCs because they prove malicious code is present. Repeated port-scanning activity is an indicator of attack-it signals hostile intent but not necessarily a successful breach. A configuration baseline requirement and routine backup logs are normal administrative records, not evidence of compromise.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an IOC (Indicator of Compromise)?
Open an interactive chat with Bash
Why is a SHA-256 hash matching a malware signature considered an IOC?
Open an interactive chat with Bash
What is the difference between an IOC and an IOA?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .