nerdexam
Cisco

200-201 · Question #249

A security engineer notices confidential data being exfiltrated to a domain 'Ransome4144- mware73-978' address that is attributed to a known advanced persistent threat group. The engineer discovers th

The correct answer is C. action on objectives. In this scenario, the attacker has already gained access to the victim's network and is exfiltrating confidential data to a known domain attributed to an advanced persistent threat group. Therefore, the attack has progressed beyond the initial stages of reconnaissance, weaponizat

Submitted by tom_us· Mar 6, 2026Security Concepts

Question

A security engineer notices confidential data being exfiltrated to a domain 'Ransome4144- mware73-978' address that is attributed to a known advanced persistent threat group. The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?

Options

  • Areconnaissance
  • Bdelivery
  • Caction on objectives
  • Dweaponization

How the community answered

(24 responses)
  • A
    4% (1)
  • C
    92% (22)
  • D
    4% (1)

Explanation

In this scenario, the attacker has already gained access to the victim's network and is exfiltrating confidential data to a known domain attributed to an advanced persistent threat group. Therefore, the attack has progressed beyond the initial stages of reconnaissance, weaponization, delivery, and exploitation. The attacker has already achieved their objective, which is to exfiltrate sensitive

Topics

#Cyber Kill Chain#APT#data exfiltration#incident classification

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice