Home > Blog > CompTIA CySA+ Certification Exam > Identifying Indicators of Compromise (IoCs) in CySA+ Labs

Identifying Indicators of Compromise (IoCs) in CySA+ Labs

Deep Dive Cert Sensei Team 2026-09-02 6 min read

Identifying IoCs involves recognizing specific forensic artifacts—such as known malicious IP addresses, unusual registry changes, unexpected outbound traffic, or specific file hashes—that indicate a high probability of a system compromise.

#IoC #CySA+ #Digital Forensics #Network Security #Host-based Security

What is an Indicator of Compromise?

An IoC is a piece of digital forensics data that suggests a system has been breached. They are the breadcrumbs left behind by attackers.

Common IoCs include unfamiliar outbound network connections, unexpected software installations, unexplained administrative account creation, and the presence of known malware signatures.

Host-Based vs. Network-Based IoCs

Host-based IoCs are found on the endpoint itself. Examples include modified registry keys, unusual processes running from temporary directories, or specific file hashes.

Network-based IoCs are observed in traffic. These include connections to known command-and-control (C2) servers, unusual protocol usage over standard ports (like SSH over port 443), or large, unexplained data exfiltration.

Hunting for IoCs in a Lab

In a CySA+ practical scenario, you must know where to look. Use tools like Sysinternals (Process Explorer, Autoruns) to hunt for host-based IoCs, and Wireshark or Zeek for network-based IoCs.

Practice correlating these findings. For example, if you find a suspicious file hash (host IoC), pivot to your network logs to see if that machine has recently communicated with a known bad IP (network IoC).

Translating Knowledge to the Exam

The CySA+ exam will present you with logs or system outputs and ask you to identify the IoC. This requires quick recognition of abnormal patterns.

To build this reflex, consistent practice is required. Leveraging tools like Cert Sensei can expose you to a wide variety of IoC scenarios, training your eye to spot anomalies quickly and accurately.

❓ Frequently Asked Questions

What is an Indicator of Compromise (IoC)?

An IoC is a piece of digital forensics data, such as an unfamiliar outbound connection or unusual registry change, that suggests a system has been breached.


What is an example of a host-based IoC?

Host-based IoCs include modified registry keys, unusual processes running from temporary directories, or malicious file hashes found on an endpoint.


What tools can be used to hunt for network-based IoCs?

Tools like Wireshark or Zeek are effective for hunting network-based IoCs, such as connections to known C2 servers or unusual protocol usage.

More from CompTIA CySA+ Certification Exam

🧠

Test Your Knowledge

Ready to practice CySA+ Certification Exam? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free