nerdexam
Cisco

200-201 · Question #170

Drag and Drop Question Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model. Answer:

Sign in or unlock 200-201 to reveal the answer and full explanation for question #170. The question stem and answer options stay visible for context.

Submitted by devops_kid· Mar 6, 2026Threat Intelligence and Incident Response - Understanding attack frameworks and intrusion event classification (e.g., CompTIA CySA+, Security+, or EC-Council CEH domain)

Question

Drag and Drop Question Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model. Answer:

Exhibit

200-201 question #170 exhibit

Answer Area

Drag items

The threat actor takes actions to violate data integrity and availability.The targeted environment is taken advantage of triggering the threat actor's code.Backdoor is placed on the victim system allowing the threat actor to maintain the persistence.An outbound connection is established to an Internet-based controller server.

Unlock 200-201 to see the answer

You've previewed enough free 200-201 questions. Unlock 200-201 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Cyber Kill Chain#Intrusion Phases#Threat Intelligence#Attack Lifecycle
Full 200-201 Practice