nerdexam
Cisco

200-201 · Question #170

Drag and Drop Question Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model. Answer:

The correct answer is The targeted environment is taken advantage of triggering the threat actor's code.; Backdoor is placed on the victim system allowing the threat actor to maintain the persistence.; An outbound connection is established to an Internet-based controller server.; The threat actor takes actions to violate data integrity and availability. The Cyber Kill Chain model defines sequential phases of a cyberattack. 'Exploitation' is where the targeted environment is taken advantage of to trigger the threat actor's code. 'Installation' follows, where a backdoor is placed on the victim system for persistence. 'Command &…

Submitted by devops_kid· Mar 6, 2026Threat Intelligence and Incident Response - Understanding attack frameworks and intrusion event classification (e.g., CompTIA CySA+, Security+, or EC-Council CEH domain)

Question

Drag and Drop Question Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model. Answer:

Exhibit

200-201 question #170 exhibit

Answer Area

Drag items

The threat actor takes actions to violate data integrity and availability.The targeted environment is taken advantage of triggering the threat actor's code.Backdoor is placed on the victim system allowing the threat actor to maintain the persistence.An outbound connection is established to an Internet-based controller server.

Correct arrangement

  • The targeted environment is taken advantage of triggering the threat actor's code.
  • Backdoor is placed on the victim system allowing the threat actor to maintain the persistence.
  • An outbound connection is established to an Internet-based controller server.
  • The threat actor takes actions to violate data integrity and availability.

Explanation

The Cyber Kill Chain model defines sequential phases of a cyberattack. 'Exploitation' is where the targeted environment is taken advantage of to trigger the threat actor's code. 'Installation' follows, where a backdoor is placed on the victim system for persistence. 'Command & Control (C2)' involves establishing an outbound connection to an internet-based controller server, and 'Actions on Objectives' is the final phase where the threat actor violates data integrity and availability to achieve their goals.

Topics

#Cyber Kill Chain#Intrusion Phases#Threat Intelligence#Attack Lifecycle

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice