nerdexam
Cisco

200-201 · Question #258

Refer to the exhibit. A security analyst is investigating unusual activity from an unknown IP address Which type of evidence is this file1?

The correct answer is A. indirect evidence. The file from an unknown IP address is likely indirect evidence because it does not directly prove a fact but instead provides circumstances from which a fact can be reasonably inferred with further analysis.

Submitted by javi_es· Mar 6, 2026Host-Based Analysis

Question

Refer to the exhibit. A security analyst is investigating unusual activity from an unknown IP address Which type of evidence is this file1?

Exhibit

200-201 question #258 exhibit

Options

  • Aindirect evidence
  • Bbest evidence
  • Ccorroborative evidence
  • Ddirect evidence

How the community answered

(35 responses)
  • A
    91% (32)
  • B
    3% (1)
  • C
    6% (2)

Why each option

The file from an unknown IP address is likely indirect evidence because it does not directly prove a fact but instead provides circumstances from which a fact can be reasonably inferred with further analysis.

Aindirect evidenceCorrect

Indirect evidence, also known as circumstantial evidence, does not directly prove a central fact but rather provides supporting circumstances from which a fact can be logically deduced. A file from an unknown IP requires additional analysis and correlation with other evidence to establish its true nature and significance in an investigation, making it an inferential piece of evidence.

Bbest evidence

Best evidence refers to the most original or reliable form of evidence, which is a quality of evidence, not its inferential nature, and a random file isn't inherently 'best' without context.

Ccorroborative evidence

Corroborative evidence supports or confirms other evidence, but the question asks about the type of *this* specific file's evidence on its own, not its relationship to other evidence.

Ddirect evidence

Direct evidence directly proves a fact without the need for inference (e.g., an eyewitness or a log explicitly stating an event occurred), which an unexplained file from an unknown IP does not do on its own.

Concept tested: Types of digital evidence

Topics

#forensics#evidence types#incident investigation

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice