nerdexam
Cisco

200-201 · Question #188

A user received an email attachment named "Hr405-report2609-empl094.exe" but did not run it. Which category of the cyber kill chain should be assigned to this type of event?

The correct answer is D. delivery. The event where a user received a malicious email attachment but did not run it falls under the 'Delivery' phase of the cyber kill chain.

Submitted by skyler.x· Mar 6, 2026Security Concepts

Question

A user received an email attachment named "Hr405-report2609-empl094.exe" but did not run it. Which category of the cyber kill chain should be assigned to this type of event?

Options

  • Ainstallation
  • Breconnaissance
  • Cweaponization
  • Ddelivery

How the community answered

(32 responses)
  • A
    3% (1)
  • C
    6% (2)
  • D
    91% (29)

Why each option

The event where a user received a malicious email attachment but did not run it falls under the 'Delivery' phase of the cyber kill chain.

Ainstallation

The 'Installation' phase occurs after successful exploitation, when the attacker establishes persistence on the target system, which did not happen here as the file was not run.

Breconnaissance

The 'Reconnaissance' phase involves gathering information about the target, which happens before the delivery of a payload.

Cweaponization

The 'Weaponization' phase involves combining an exploit with a payload into a deliverable package, which occurs before the delivery to the victim.

DdeliveryCorrect

In the cyber kill chain, the 'Delivery' phase involves transmitting the weaponized artifact (the malicious executable attachment) to the target. Receiving the email attachment completes this phase, regardless of whether it was executed.

Concept tested: Cyber Kill Chain - Delivery phase

Source: https://learn.microsoft.com/en-us/azure/sentinel/fusion-detection

Topics

#cyber kill chain#malware delivery#email security#attack lifecycle

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice