mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: Based on the exhibit, what action should the…
Exhibit
Refer to the exhibit. [**] [1:2000002:3] ET MALWARE Possible Malicious Download [**] [Priority: 2] 12/10/2023-10:45:23.456789 192.168.1.10:45678 -> 203.0.113.5:80 TCP TTL:64 TOS:0x0 ID:12345 IpLen:20 DgmLen:1500 DF ***A**** Seq: 0x12345678 Ack: 0x9ABCDEF0 Win: 0x2000 TcpLen: 20 [Xref => http://malware.example.com/samples/abc123]
Based on the exhibit, what action should the analyst take to further investigate this alert?
⚠ Common exam trap
Cisco often tests the misconception that signature-based alerts are definitive, leading candidates to choose options like searching the PCAP for the same signature ID, when the real next step is to pivot from the alert's metadata (e.g., URL) to retrieve and analyze the actual payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Extract the URL from the alert and check the file hash.
The analyst should extract the URL from the alert and check the file hash because the alert indicates a potential malware download via HTTP. By retrieving the file referenced in the URL, the analyst can compute its hash (e.g., MD5, SHA256) and compare it against known threat intelligence databases (e.g., VirusTotal) to confirm maliciousness and identify the specific malware family. This directly validates whether the detected event is a true positive and provides actionable indicators for containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Extract the URL from the alert and check the file hash.
Why this is correct
The reference URL provides direct access to potential malware.
- ✗
Search the PCAP for the same signature ID.
Why it's wrong here
Searching for the same signature ID may not provide new information.
- ✗
Perform a DNS lookup on the destination IP.
Why it's wrong here
DNS lookup may not reveal malicious intent without additional context.
- ✗
Check the firewall logs for any blocked connections.
Why it's wrong here
Firewall logs may not contain the specific URL context.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.