nerdexam
Cisco

200-201 · Question #260

A user received a targeted spear-phishing email and identified it as suspicious before opening the content. To which category of the Cyber Kill Chain model does to this type of event belong?

The correct answer is B. delivery. In the Cyber Kill Chain model, the "Delivery" stage involves the initial point at which an attacker delivers a weaponized payload, such as a phishing email or malware-infected attachment, to the intended target. When the user receives the spear-phishing email, it represents the…

Submitted by kim_seoul· Mar 6, 2026Security Monitoring

Question

A user received a targeted spear-phishing email and identified it as suspicious before opening the content. To which category of the Cyber Kill Chain model does to this type of event belong?

Options

  • Aweaponization
  • Bdelivery
  • Cexploitation
  • Dreconnaissance

How the community answered

(44 responses)
  • A
    9% (4)
  • B
    84% (37)
  • C
    2% (1)
  • D
    5% (2)

Explanation

In the Cyber Kill Chain model, the "Delivery" stage involves the initial point at which an attacker delivers a weaponized payload, such as a phishing email or malware-infected attachment, to the intended target. When the user receives the spear-phishing email, it represents the delivery of the malicious content to the victim's email inbox, even if the user identifies it as suspicious before

Topics

#cyber kill chain#spear-phishing#delivery phase

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice