Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 2 Question 69 Discussion

A security engineer notices confidential data being exfiltrated to a domain "Ranso4134-mware31-895" address that is attributed to a known advanced persistent threat group The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?
D) weaponization
A) reconnaissance
B) delivery
C) action on objectives

Cisco 200-201 Exam - Topic 2 Question 69 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 69
Topic #: 2
[All 200-201 Questions]

A security engineer notices confidential data being exfiltrated to a domain "Ranso4134-mware31-895" address that is attributed to a known advanced persistent threat group The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Lizbeth
10 months ago
Are we sure it's not just a misconfiguration?
upvoted 0 times
...
Reita
10 months ago
Seems like a classic case of weaponization to me.
upvoted 0 times
...
Macy
10 months ago
Wow, I can't believe they got that far!
upvoted 0 times
...
Gerald
11 months ago
I think it's delivery, though.
upvoted 0 times
...
Cristy
11 months ago
This is definitely action on objectives.
upvoted 0 times
...
Owen
11 months ago
I feel like "weaponization" doesn't fit here at all, but I'm confused about the difference between "delivery" and "action on objectives."
upvoted 0 times
...
Madonna
11 months ago
I'm leaning towards "action on objectives" too, but what if it's considered "reconnaissance" if they were just gathering data first?
upvoted 0 times
...
Leonida
11 months ago
I remember practicing a question similar to this, and I think "delivery" was about getting the payload in, not the actual data theft.
upvoted 0 times
...
Kenny
11 months ago
I think this might be "action on objectives" since the data is being exfiltrated, but I'm not entirely sure.
upvoted 0 times
...
Rosamond
11 months ago
Hmm, I'm not too familiar with NG MVPN, so I'm a bit unsure about the specifics here. I'll need to review my notes on multicast routing protocols to try to figure this out.
upvoted 0 times
...
Marvel
11 months ago
Wait, I'm a little confused. There are so many steps listed, and the options seem to overlap. I better review my notes on incident management to make sure I understand the proper sequence before answering.
upvoted 0 times
...
Brianne
11 months ago
Hmm, the lack of suspicious logs and failed login attempts is really throwing me off. I'm not sure what could be causing the lack of visibility.
upvoted 0 times
...
Tomas
11 months ago
This question seems straightforward. I'll carefully read through the options and eliminate the one that is not part of the proper handling of a stop payment.
upvoted 0 times
...
Luis
11 months ago
This looks like a tricky IPv6 access list question. I'll need to carefully review the configuration and options to determine the best solution.
upvoted 0 times
...
Tonja
11 months ago
I'm leaning towards option D, but I'm not entirely certain. I think both the flat rate and aggregate method can apply, so that could make sense in this scenario.
upvoted 0 times
...

Save Cancel