200-201 Security Monitoring Practice Question
Which THREE of the following are common Indicators of Compromise (IoCs) used in threat intelligence?
⚠ Common exam trap
Cisco often tests the distinction between IoCs (specific, observable artifacts of an intrusion) and contextual data (like user-agent strings or port numbers) that are not reliable or specific enough to be used as standalone indicators in threat intelligence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP addresses
IP addresses (A) are a classic network-based IoC because threat intelligence feeds track malicious or command-and-control (C2) infrastructure by IP, allowing defenders to block or alert on traffic to known-bad hosts. Domain names (D) are equally common IoCs, used to identify malicious domains, C2 servers, and phishing sites via DNS monitoring, sinkholing, or blocklists. File hashes such as MD5 and SHA-256 (E) are host-based IoCs that uniquely identify known malicious files, enabling endpoint and antivirus tools to detect malware by exact signature. User-agent strings (B) can be suspicious artifacts but are not typically standalone IoCs since they are trivially spoofed and highly variable, and port numbers (C) are not reliable IoCs on their own because legitimate and malicious services frequently share the same ports (e.g., 80, 443).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IP addresses
Why this is correct
IP addresses are network-layer artefacts recorded in firewall, IDS and proxy logs, letting analysts block or correlate malicious hosts. They satisfy the IoC requirement because they are observable, machine-readable evidence that a compromise may have occurred.
- ✗
User-agent strings
Why it's wrong here
User-agent strings are legitimate HTTP header values, so their presence alone does not evidence compromise; only a specific malicious string would qualify. They are tempting because threat feeds do list known-malicious user agents, and they help detect suspicious tooling, but the stem asks for common IoC categories, which centre on hashes, IPs and domains.
- ✗
Port numbers
Why it's wrong here
Port numbers describe transport-layer endpoints, not artefacts left by an intrusion, so they cannot indicate compromise on their own. They are tempting because malicious traffic often uses unusual ports, making them useful for firewall rule design and anomaly baselining, but IoCs require observable evidence such as hashes, domains or IP addresses.
- ✓
Domain names
Why this is correct
Malicious or algorithmically generated domain names, such as those produced by domain generation algorithms, appear in threat intelligence feeds as network-based IoCs. They satisfy the stem's requirement for a common IoC category, since defenders hunt for DNS queries resolving to known command-and-control domains, alongside IP addresses and file hashes.
- ✓
File hashes (MD5, SHA-256)
Why this is correct
Cryptographic file hashes such as MD5 and SHA-256 uniquely identify known malicious files, enabling endpoint and antivirus tools to detect them regardless of filename. They satisfy the IoC requirement as precise, machine-readable evidence of compromise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.