easyMultiple SelectObjective-mapped
200-201 Practice Question: Which two pieces of evidence are strong…
Which two pieces of evidence are strong indicators of compromise (IOC) in network traffic?
⚠ Common exam trap
Cisco often tests the distinction between 'normal' traffic and 'anomalous' traffic, and the trap here is that candidates may mistake encrypted traffic (Option B) as always suspicious, but the question asks for 'strong indicators' — and unrecognized SSL certificates are indeed a strong IOC, while regular DNS, SMTP, and CDN traffic are not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Communication with a known malicious IP address
Communication with a known malicious IP address is a strong indicator of compromise because it directly suggests the host is interacting with a command-and-control (C2) server or a malware distribution point. Threat intelligence feeds and blocklists (e.g., AlienVault OTX, MISP) provide curated lists of known malicious IPs; matching traffic to these lists provides high-fidelity evidence of an active compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Communication with a known malicious IP address
Why this is correct
Malicious IPs are direct IOCs.
- ✓
Encrypted traffic using unrecognized SSL certificates
Why this is correct
Unrecognized certificates may indicate man-in-the-middle or malicious servers.
- ✗
Regular DNS queries to corporate DNS servers
Why it's wrong here
This is normal network behavior.
- ✗
Normal SMTP traffic to internal mail server
Why it's wrong here
Internal email traffic is benign.
- ✗
Standard HTTP traffic to a known content delivery network
Why it's wrong here
CDN traffic is normal and expected.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.