Courseiva
Security Monitoring →easyMultiple Choice

200-201 Security Monitoring Practice Question

A security analyst is examining a suspicious file and wants to determine its reputation and threat score. Which Cisco security solution should the analyst use to query the file's SHA-256 hash and get a verdict?

⚠ Common exam trap

The trap here is assuming that Cisco Umbrella can provide file hash reputation because it offers security intelligence, but its primary function is DNS-layer enforcement, not file analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco Threat Grid

Cisco Threat Grid is designed for malware analysis and threat intelligence, allowing analysts to submit file hashes and receive a threat score and behavioral report. The other options focus on DNS security, identity management, or network flow analysis, none of which provide file hash reputation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cisco Umbrella

    Why it's wrong here

    Cisco Umbrella primarily provides DNS-layer security and does not offer file hash reputation lookup. While it can block malicious domains, it is not designed for analyzing file hashes or providing threat scores for files. Thus, it is not the right tool for this task.

  • ✗

    Cisco Identity Services Engine

    Why it's wrong here

    Cisco Identity Services Engine (ISE) is used for network access control and identity management. It does not provide file reputation or threat scoring capabilities. Its focus is on authentication and authorization, so it would not help in determining a file's threat score.

  • ✗

    Cisco Stealthwatch

    Why it's wrong here

    Cisco Stealthwatch is a network traffic analysis tool that uses flow data to detect anomalies. It does not analyze files or provide hash reputation. While it can detect suspicious network behavior, it lacks the file analysis features needed for this scenario.

  • ✓

    Cisco Threat Grid

    Why this is correct

    Cisco Threat Grid is a malware analysis and threat intelligence platform that allows analysts to submit files or hashes to obtain a threat score and behavioral analysis. It provides detailed reports on file reputation, making it the appropriate tool for this scenario.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.