Courseiva
Security Monitoring →mediumMultiple Select

200-201 Security Monitoring Practice Question

An analyst is investigating a potential compromise using Indicators of Compromise (IoCs). Which TWO of the following are valid types of IoCs?

⚠ Common exam trap

Cisco often tests the distinction between an IoC (a specific, observable artifact of compromise) and contextual or behavioral data (like usernames or geographic locations) that may be useful in an investigation but are not valid IoCs themselves.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP address

Option B (IP address) is a valid IoC because a specific IP address associated with command-and-control (C2) servers, malicious scanning, or exfiltration traffic is a concrete, observable network artifact that analysts can search for in firewall, IDS/IPS, and proxy logs. Option D (File hash (MD5)) is a valid IoC because a cryptographic hash such as an MD5 digest uniquely identifies a known malicious file, allowing endpoint and antivirus tools to detect that exact sample without relying on its filename. By contrast, option A (User name) is generally not an IoC by itself, since usernames are not inherently malicious and are too common to serve as reliable compromise indicators. Option C (Geographic location) is not a valid IoC type on its own, as geolocation is a derived attribute of an IP address rather than a distinct indicator. Option E (Protocol name) is not a valid IoC, because protocols like HTTP or DNS are legitimate, ubiquitous communication methods and only become suspicious in specific contexts, not as standalone indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User name

    Why it's wrong here

    A user name is an identity attribute present in normal activity, not evidence of malicious behaviour, so it cannot by itself indicate compromise. It is tempting because compromised accounts are central to investigations, yet the IoC is the observable tied to that account, such as an anomalous authentication source or impossible-travel event.

  • ✓

    IP address

    Why this is correct

    An IP address is a network-level IoC, recording the source or destination of malicious traffic such as command-and-control contact. It satisfies the stem's requirement for a valid IoC type because it provides concrete, observable evidence of compromise that analysts can correlate across logs and block at perimeter controls.

  • ✗

    Geographic location

    Why it's wrong here

    Geographic location describes where activity originated, not an artefact left by an intrusion, so it cannot itself indicate compromise. It is tempting because geolocation anomalies often accompany account takeover, but that context derives from IP addresses, which are the actual IoC; location alone is derived intelligence.

  • ✓

    File hash (MD5)

    Why this is correct

    A file hash such as MD5 is a valid host-based IoC: it uniquely identifies known malicious files, letting the analyst search endpoints and logs for that exact artefact. This satisfies the stem's requirement for a concrete, observable indicator of compromise during investigation.

  • ✗

    Protocol name

    Why it's wrong here

    A protocol name such as HTTP or SMB is a legitimate communication standard, not an observable artefact of an intrusion. It is tempting because attackers abuse common protocols, but the IoC is the specific value within that traffic, such as a malicious URI, user agent string, or JA3 fingerprint, not the protocol label.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.