nerdexam
Cisco

200-201 · Question #125

A security specialist notices 100 HTTP GET and POST requests for multiple pages on the web servers. The agent in the requests contains PHP code that, if executed, creates and writes to a new PHP…

The correct answer is C. installation. In this context, the malicious PHP code embedded within the HTTP requests attempts to create and write a new PHP file on the webserver. This act aligns with the "Installation" category, as it involves the unauthorized placement and execution of code or files on the targeted…

Submitted by cyberguy42· Mar 6, 2026Host-Based Analysis

Question

A security specialist notices 100 HTTP GET and POST requests for multiple pages on the web servers. The agent in the requests contains PHP code that, if executed, creates and writes to a new PHP file on the webserver. Which event category is described?

Options

  • Areconnaissance
  • Baction on objectives
  • Cinstallation
  • Dexploitation

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    85% (33)
  • D
    8% (3)

Explanation

In this context, the malicious PHP code embedded within the HTTP requests attempts to create and write a new PHP file on the webserver. This act aligns with the "Installation" category, as it involves the unauthorized placement and execution of code or files on the targeted system, which is a step towards establishing a foothold for further exploitation or control by the attacker.

Topics

#attack kill chain#web server compromise#installation phase#malware deployment

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice