Courseiva
Security Monitoring →easyMultiple Choice

200-201 Security Monitoring Practice Question

A security analyst is examining a suspicious file and calculates its SHA-256 hash. The analyst then queries Cisco Talos Intelligence for the hash. The result shows that the file is known malware with a detection name of 'Trojan.GenericKD.123456'. Which of the following does this result indicate?

⚠ Common exam trap

The trap here is thinking that a hash match requires further validation or that it only indicates similarity, when in fact it is a definitive identification of the exact file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file is confirmed malicious and matches a known malware signature in the Talos database.

Cisco Talos Intelligence provides reputation and threat data for files, IPs, and domains. When a SHA-256 hash is queried and returns a known malware detection, it means the exact file has been previously analyzed and confirmed malicious. This is a reliable indicator, and the analyst should proceed with containment and remediation. Other options either misinterpret the result or assume actions that are not part of the query process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The file is confirmed malicious and matches a known malware signature in the Talos database.

    Why this is correct

    Cisco Talos Intelligence maintains a database of file hashes associated with malware. When a hash query returns a known malware detection name, it means the exact file has been previously identified as malicious. This is a strong indicator that the file is indeed malware, and the analyst should treat it as such, initiating incident response procedures.

  • ✗

    The file is benign but has a similar hash to known malware.

    Why it's wrong here

    Cryptographic hashes are unique; if the SHA-256 hash matches a known malware sample, the file is identical to that sample. There is no 'similar hash' in this context; hash collisions are extremely rare and not applicable here. The result indicates a definitive match, so the file is malicious, not benign.

  • ✗

    The file is suspicious but requires further dynamic analysis to confirm maliciousness.

    Why it's wrong here

    While dynamic analysis can provide additional context, a match in Talos for a SHA-256 hash is a definitive indicator of malware. The file is not merely suspicious; it is confirmed malicious based on the hash. Further analysis may be useful for understanding behavior, but it is not required to confirm maliciousness.

  • ✗

    The file has been quarantined by Cisco AMP for Endpoints automatically.

    Why it's wrong here

    Querying Talos Intelligence does not trigger any automatic action on endpoints. Talos is a threat intelligence service, not an endpoint management tool. The result only provides information; it does not indicate that the file has been quarantined. The analyst must take manual action if needed.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.