Which THREE of the following are common Indicators of Compromise (IoCs) used in threat intelligence?
IP addresses are network-layer artefacts recorded in firewall, IDS and proxy logs, letting analysts block or correlate malicious hosts. They satisfy the IoC requirement because they are observable, machine-readable evidence that a compromise may have occurred.
Why this answer
IP addresses (A) are a classic network-based IoC because threat intelligence feeds track malicious or command-and-control (C2) infrastructure by IP, allowing defenders to block or alert on traffic to known-bad hosts. Domain names (D) are equally common IoCs, used to identify malicious domains, C2 servers, and phishing sites via DNS monitoring, sinkholing, or blocklists. File hashes such as MD5 and SHA-256 (E) are host-based IoCs that uniquely identify known malicious files, enabling endpoint and antivirus tools to detect malware by exact signature.
User-agent strings (B) can be suspicious artifacts but are not typically standalone IoCs since they are trivially spoofed and highly variable, and port numbers (C) are not reliable IoCs on their own because legitimate and malicious services frequently share the same ports (e.g., 80, 443).
Exam trap
Cisco often tests the distinction between IoCs (specific, observable artifacts of an intrusion) and contextual data (like user-agent strings or port numbers) that are not reliable or specific enough to be used as standalone indicators in threat intelligence.