exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 204 discussion

Actual exam question from Cisco's 200-201
Question #: 204
Topic #: 1
[All 200-201 Questions]

A security engineer notices confidential data being exfiltrated to a domain `Ransome4144-mware73-978` address that is attributed to a known advanced persistent threat group. The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?

  • A. reconnaissance
  • B. delivery
  • C. action on objectives
  • D. weaponization
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SecurityGuy
9 months, 3 weeks ago
Selected Answer: C
Actions on Objectives. Intruder takes action to achieve their goals, such as data exfiltration, data destruction, or encryption for ransom. https://en.wikipedia.org/wiki/Kill_chain
upvoted 1 times
...
drdecker100
1 year, 3 months ago
Selected Answer: C
n this scenario, the attacker has already gained access to the victim's network and is exfiltrating confidential data to a known domain attributed to an advanced persistent threat group. Therefore, the attack has progressed beyond the initial stages of reconnaissance, weaponization, delivery, and exploitation. The attacker has already achieved their objective, which is to exfiltrate sensitive data.
upvoted 3 times
...
Eng_ahmedyoussef
1 year, 8 months ago
Selected Answer: C
C. action on objectives
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...