Cisco
300-215 · Question #34
Refer to the exhibit. What is the indicator of compromise?
The correct answer is A. SHA256 file hash. The STIX indicator’s pattern field specifies a SHA-256 hash value used to identify the ransomware sample - that hash is the actual indicator of compromise.
Submitted by emma.c· Mar 6, 2026Incident Response Techniques
Question
Refer to the exhibit. What is the indicator of compromise?
Exhibit
Options
- ASHA256 file hash
- Bindicator ID: malware--a932fcc6-e032-476c-826f-cb970a569bce
- Cindicator type: malicious-activity
- DMD5 file hash
How the community answered
(20 responses)- A90% (18)
- B5% (1)
- D5% (1)
Explanation
The STIX indicator’s pattern field specifies a SHA-256 hash value used to identify the ransomware sample - that hash is the actual indicator of compromise.
Topics
#IOC#file hash#malware analysis
Community Discussion
No community discussion yet for this question.
