nerdexam
Cisco

200-201 · Question #399

During a quarterly vulnerability scan, a security analyst discovered unused uncommon ports open and in a listening state. Further investigation showed that the unknown application was communicating…

The correct answer is B. Actions on Objectives. The detection of command and control communication on an infected server, along with unused open ports and encrypted external communication, indicates the attacker is in the 'Actions on Objectives' phase, having already established a foothold and performing post-exploitation…

Submitted by layla.eg· Mar 6, 2026Network Intrusion Analysis

Question

During a quarterly vulnerability scan, a security analyst discovered unused uncommon ports open and in a listening state. Further investigation showed that the unknown application was communicating with an external IP address on an encrypted channel. A deeper analysis revealed a command and control communication on an infected server. At which step of the Cyber Kill Chain was the attack detected?

Options

  • AExploitation
  • BActions on Objectives
  • CWeaponization
  • DDelivery

How the community answered

(55 responses)
  • A
    15% (8)
  • B
    73% (40)
  • C
    4% (2)
  • D
    9% (5)

Why each option

The detection of command and control communication on an infected server, along with unused open ports and encrypted external communication, indicates the attacker is in the 'Actions on Objectives' phase, having already established a foothold and performing post-exploitation activities.

AExploitation

Exploitation is the step where the attacker successfully breaches a vulnerability to gain access, but the C2 communication indicates a phase after initial exploitation.

BActions on ObjectivesCorrect

The discovery of command and control (C2) communication on an infected server signifies that the attacker has successfully gained access (exploitation), established a persistent presence (installation), and is now communicating with their remote infrastructure to achieve their ultimate goals. This activity falls under the 'Actions on Objectives' phase of the Cyber Kill Chain, where the attacker executes commands to achieve their ultimate mission, such as data exfiltration or further compromise.

CWeaponization

Weaponization is the phase where the attacker bundles an exploit with a backdoor into a deliverable payload, which occurs before delivery and exploitation.

DDelivery

Delivery is the phase where the weaponized payload is transmitted to the victim, occurring before exploitation and C2 communication.

Concept tested: Cyber Kill Chain phases - Actions on Objectives

Source: https://www.microsoft.com/en-us/security/business/security-intelligence/what-is-cyber-kill-chain

Topics

#Cyber Kill Chain#Command and Control#Incident detection

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice