200-201 exam dumps

200-201 practice question 398 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 398

Select 3

A security analyst is investigating an intrusion event where an attacker successfully sent a phishing email to a company employee, tricking them into providing their login credentials. These credentials were later used by the attacker to access the company's internal servers and exfiltrate sensitive data. Based on the Cyber Kill Chain model, which of the following stages are involved in this scenario?

  1. A

    Reconnaissance

  2. B

    Delivery

  3. C

    Exploitation

  4. D

    Command and Control

  5. E

    Actions on Objectives

Show answer and explanation

Correct answers: B, C, E

Explanation

The Cyber Kill Chain model helps classify intrusion events into stages. In this scenario, the attacker delivered the phishing email (Delivery), exploited the employee's trust to gain credentials (Exploitation), and used those credentials to achieve their objective of accessing internal servers and stealing data (Actions on Objectives). Other stages such as Reconnaissance and Command and Control are not directly described in this specific case.

  • A. Incorrect.

    Reconnaissance involves the attacker gathering information to identify potential targets, such as scanning for vulnerabilities or researching the organization. While this is a common step, it is not explicitly described in the given scenario.

  • B. Correct.

    Delivery refers to the attacker sending the phishing email to the employee, which is clearly a part of the described intrusion event.

  • C. Correct.

    Exploitation occurs when the employee falls for the phishing email and provides their login credentials, enabling further compromise by the attacker.

  • D. Incorrect.

    Command and Control involves establishing a persistent connection between the attacker and the compromised system. This step is not explicitly mentioned in the scenario.

  • E. Correct.

    Actions on Objectives refers to the attacker using the stolen credentials to access internal servers and exfiltrate sensitive data, which is a direct part of the described intrusion event.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam