nerdexam
Cisco

300-215 · Question #34

Refer to the exhibit. What is the indicator of compromise?

The correct answer is A. SHA256 file hash. The STIX indicator’s pattern field specifies a SHA-256 hash value used to identify the ransomware sample - that hash is the actual indicator of compromise.

Submitted by emma.c· Mar 6, 2026Incident Response Techniques

Question

Refer to the exhibit. What is the indicator of compromise?

Exhibit

300-215 question #34 exhibit

Options

  • ASHA256 file hash
  • Bindicator ID: malware--a932fcc6-e032-476c-826f-cb970a569bce
  • Cindicator type: malicious-activity
  • DMD5 file hash

How the community answered

(20 responses)
  • A
    90% (18)
  • B
    5% (1)
  • D
    5% (1)

Explanation

The STIX indicator’s pattern field specifies a SHA-256 hash value used to identify the ransomware sample - that hash is the actual indicator of compromise.

Topics

#IOC#file hash#malware analysis

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice