nerdexam
Cisco

200-201 · Question #34

A user received a malicious attachment but did not run it. Which category classifies the intrusion?

The correct answer is D. delivery. If a user receives a malicious attachment but does not execute it, the intrusion has reached the delivery stage of the Cyber Kill Chain.

Submitted by yuriko_h· Mar 6, 2026Security Concepts

Question

A user received a malicious attachment but did not run it. Which category classifies the intrusion?

Options

  • Aweaponization
  • Breconnaissance
  • Cinstallation
  • Ddelivery

How the community answered

(31 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    94% (29)

Why each option

If a user receives a malicious attachment but does not execute it, the intrusion has reached the delivery stage of the Cyber Kill Chain.

Aweaponization

Weaponization is the stage where the attacker combines an exploit and a backdoor into a deliverable payload, occurring before delivery.

Breconnaissance

Reconnaissance is the initial stage where an attacker gathers information about the target, which happens long before a malicious attachment is sent.

Cinstallation

Installation refers to the stage where the attacker installs persistent access to the victim's system, which requires the malicious attachment to be executed, which did not occur here.

DdeliveryCorrect

Delivery is the stage in the Cyber Kill Chain where the attacker transmits the weaponized malware to the victim, such as via an email attachment, signifying successful delivery even if not executed.

Concept tested: Cyber Kill Chain - Delivery Stage

Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html

Topics

#cyber kill chain#attack phases#malware delivery

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice