Which statement about IOC goals is true?

Prepare for the SANS FOR508 Exam. Use flashcards and multiple-choice questions, each with hints and explanations. Maximize your readiness for the test!

Multiple Choice

Which statement about IOC goals is true?

Explanation:
Indicator of Compromise design hinges on balancing precision with breadth. You want detections that are specific enough to avoid false positives, yet broad enough to catch related indicators across variants and changing attack patterns. Relying only on static hashes is too narrow because malware often mutates, renames files, or uses new infrastructure, so a detection based on hashes alone misses many threats. Conversely, aiming to maximize detections with no regard to false positives would flood analysts with alerts and reduce their effectiveness. Automation is a practical part of IOC work, enabling timely collection and updating of indicators, but the essential goal remains achieving enough breadth to cover variants while maintaining acceptable precision to keep false positives manageable.

Indicator of Compromise design hinges on balancing precision with breadth. You want detections that are specific enough to avoid false positives, yet broad enough to catch related indicators across variants and changing attack patterns. Relying only on static hashes is too narrow because malware often mutates, renames files, or uses new infrastructure, so a detection based on hashes alone misses many threats. Conversely, aiming to maximize detections with no regard to false positives would flood analysts with alerts and reduce their effectiveness. Automation is a practical part of IOC work, enabling timely collection and updating of indicators, but the essential goal remains achieving enough breadth to cover variants while maintaining acceptable precision to keep false positives manageable.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy