Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: Based on the exhibit, what action should the…

Exhibit

Refer to the exhibit.

[**] [1:2000002:3] ET MALWARE Possible Malicious Download [**]
[Priority: 2]
12/10/2023-10:45:23.456789 192.168.1.10:45678 -> 203.0.113.5:80
TCP TTL:64 TOS:0x0 ID:12345 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x12345678  Ack: 0x9ABCDEF0  Win: 0x2000  TcpLen: 20
[Xref => http://malware.example.com/samples/abc123]

Based on the exhibit, what action should the analyst take to further investigate this alert?

⚠ Common exam trap

Cisco often tests the misconception that signature-based alerts are definitive, leading candidates to choose options like searching the PCAP for the same signature ID, when the real next step is to pivot from the alert's metadata (e.g., URL) to retrieve and analyze the actual payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Extract the URL from the alert and check the file hash.

The analyst should extract the URL from the alert and check the file hash because the alert indicates a potential malware download via HTTP. By retrieving the file referenced in the URL, the analyst can compute its hash (e.g., MD5, SHA256) and compare it against known threat intelligence databases (e.g., VirusTotal) to confirm maliciousness and identify the specific malware family. This directly validates whether the detected event is a true positive and provides actionable indicators for containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Extract the URL from the alert and check the file hash.

    Why this is correct

    The reference URL provides direct access to potential malware.

  • Search the PCAP for the same signature ID.

    Why it's wrong here

    Searching for the same signature ID may not provide new information.

  • Perform a DNS lookup on the destination IP.

    Why it's wrong here

    DNS lookup may not reveal malicious intent without additional context.

  • Check the firewall logs for any blocked connections.

    Why it's wrong here

    Firewall logs may not contain the specific URL context.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.