Courseiva
easyMultiple SelectObjective-mapped

200-201 Practice Question: Which two pieces of evidence are strong…

Which two pieces of evidence are strong indicators of compromise (IOC) in network traffic?

⚠ Common exam trap

Cisco often tests the distinction between 'normal' traffic and 'anomalous' traffic, and the trap here is that candidates may mistake encrypted traffic (Option B) as always suspicious, but the question asks for 'strong indicators' — and unrecognized SSL certificates are indeed a strong IOC, while regular DNS, SMTP, and CDN traffic are not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Communication with a known malicious IP address

Communication with a known malicious IP address is a strong indicator of compromise because it directly suggests the host is interacting with a command-and-control (C2) server or a malware distribution point. Threat intelligence feeds and blocklists (e.g., AlienVault OTX, MISP) provide curated lists of known malicious IPs; matching traffic to these lists provides high-fidelity evidence of an active compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Communication with a known malicious IP address

    Why this is correct

    Malicious IPs are direct IOCs.

  • Encrypted traffic using unrecognized SSL certificates

    Why this is correct

    Unrecognized certificates may indicate man-in-the-middle or malicious servers.

  • Regular DNS queries to corporate DNS servers

    Why it's wrong here

    This is normal network behavior.

  • Normal SMTP traffic to internal mail server

    Why it's wrong here

    Internal email traffic is benign.

  • Standard HTTP traffic to a known content delivery network

    Why it's wrong here

    CDN traffic is normal and expected.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.