An indicator of malicious activity is an observable clue that something is wrong: an odd login, a spike in traffic, a log that should be there but is not. Security+ lists a set of indicators that often signal an attack in progress, and exam questions typically describe one or two of them and ask what is happening or what to investigate. Recognizing indicators is the everyday work of security operations center (SOC) analysts, who see them in the security information and event management (SIEM) system, identity provider logs and endpoint alerts. The goal is to connect the clue to a likely cause and a sensible next step.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.