Courseiva
mediumMatching

SC-200 Practice Question: Match each threat intelligence indicator type to…

Match each threat intelligence indicator type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

IPv4 or IPv6 address associated with malicious activity

Domain name used for phishing or C2

Full URL path involved in an attack

MD5, SHA1, or SHA256 hash of a malicious file

Sender address from a phishing campaign

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP Address: A numerical label assigned to each device connected to a computer network.

These are common STIX indicator types used in threat intelligence. Correct matches: IP Address is a numerical label, Domain Name is an identification string, File Hash is a hash of file content. Common confusions involve swapping definitions between IP and Domain, or IP and File Hash.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IP Address: A numerical label assigned to each device connected to a computer network.

    Why this is correct

    An Internet Protocol address is a structured numeric identifier—IPv4 uses 32-bit dotted-decimal notation, IPv6 uses 128-bit hexadecimal—assigned to a network interface for routing and host addressing. In threat intelligence, IP addresses are key indicators of compromise (IOCs) because they identify command-and-control servers, malicious scanners, or phishing infrastructure. They are considered 'good' indicators when contextualized, as one IP can host many unrelated services or be shared by legitimate and malicious actors.

  • ✓

    Domain Name: An identification string that defines a realm of administrative autonomy on the Internet.

    Why this is correct

    A domain name is a hierarchical, human-readable label within the DNS namespace, such as example.com, that represents a zone of administrative control and can be resolved to IP addresses via DNS records. Domain names are tactical indicators often used to track phishing sites, malware staging servers, or DNS-based C2 channels, especially when the underlying IP changes. They also enable defenders to spot patterns like typosquatting, domain generations, or newly registered malicious domains.

  • ✓

    File Hash: A string of characters produced by a hash function representing the contents of a file.

    Why this is correct

    A file hash is the fixed-length output of a cryptographic hash function (MD5, SHA-1, SHA-256) calculated over the exact bytes of a file, producing a near-unique fingerprint of that file's content. Even a one-byte change produces a completely different hash, making hashes valuable as deterministic indicators for known malware binaries or malicious documents in SIEM, sandbox, and EDR detections. However, hashes are brittle for tracking related malware because attackers can trivially alter the file to generate a new hash.

  • ✗

    IP Address: An identification string that defines a realm of administrative autonomy on the Internet.

    Why it's wrong here

    This statement incorrectly describes an IP address by giving the definition of a domain name. An IP address is a numeric, network-layer identifier used by routers to deliver packets; it is not a text-based 'realm of administrative autonomy.' Administrative autonomy over a namespace is a property of DNS domains, where an owner controls subdomains and records. Therefore, pairing 'IP Address' with this description is a concept mismatch that fails threat-indicator classification.

  • ✗

    File Hash: A numerical label assigned to each device connected to a computer network.

    Why it's wrong here

    This statement mischaracterizes a file hash because a numerical label assigned to a device is the role of an IP address, not a hash value. File hashes are computed from the file's contents through a hashing algorithm, serve to verify integrity or uniquely identify malicious samples, and are not tied to hardware or network topology. Confusing the two conflates network-layer identity with content-based fingerprinting, which is a critical distinction in indicator management.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.