200-201 Security Monitoring Practice Question
Which of the following is an example of an Indicator of Compromise (IoC)?
⚠ Common exam trap
Cisco often tests the distinction between an IoC (a specific artifact like a hash, IP, or domain) and a security tool or process (like a SIEM, firewall rule, or baseline), so candidates mistakenly classify operational components as IoCs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A file hash (SHA-256)
An Indicator of Compromise (IoC) is a piece of forensic data that identifies potentially malicious activity on a system or network. A file hash (SHA-256) is a classic IoC because it provides a unique cryptographic fingerprint of a known malicious file, allowing security tools to detect its presence across endpoints. This is a specific, actionable artifact that directly points to a compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A file hash (SHA-256)
Why this is correct
A SHA-256 file hash is a concrete, artefact-based IoC: it uniquely identifies known-malicious files, letting analysts search endpoints and logs for that exact value. Unlike behavioural heuristics, the hash is a static forensic indicator satisfying the stem's requirement for an IoC example.
- ✗
A SIEM dashboard
Why it's wrong here
A SIEM dashboard is a visualisation and correlation interface that displays alerts; it is a tool, not an observable artefact of compromise. It is tempting because dashboards surface IoCs, but the indicator itself is data such as an anomalous IP address, file hash or registry entry.
- ✗
A firewall rule
Why it's wrong here
A firewall rule is a preventive access-control configuration, not evidence that a compromise has already occurred. It is tempting because firewall logs can reveal malicious traffic, but an IoC is an observable artefact such as an unusual outbound connection, hash or registry key indicating intrusion.
- ✗
A network baseline
Why it's wrong here
A network baseline documents normal traffic patterns for comparison, so it describes expected state rather than evidence of intrusion. It is tempting because deviations from a baseline can reveal compromise, but the baseline itself is a reference measurement, whereas an IoC is an observed artefact such as a malicious hash.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.