Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is investigating an incident where an attacker gained initial access to a corporate network. The analyst finds that the attacker sent a phishing email with a link to a malicious website that exploited a vulnerability in the user's browser. Which phase of the Cyber Kill Chain does the browser exploitation represent?

⚠ Common exam trap

Watch out — candidates often confuse Delivery with Exploitation, but the delivery is the phishing email, while the actual vulnerability exploitation is the browser compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploitation

The Cyber Kill Chain phases are Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives. When a user visits a malicious website that exploits a browser vulnerability, that action is Exploitation. It follows Delivery (the phishing email with the link) and precedes Installation of any persistent payload.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Weaponization

    Why it's wrong here

    Weaponization involves creating or preparing the malicious payload, such as coupling an exploit with a deliverable like a malicious document or website. The scenario describes the actual exploitation occurring on the user's browser, which happens after weaponization. The weapon has already been delivered and is now being used, so this is not the correct phase.

  • ✗

    Installation

    Why it's wrong here

    Installation is the phase where the attacker establishes persistence on the victim's system, such as installing a backdoor or remote access trojan. The scenario describes the browser exploitation itself, which precedes any installation. The exploit may lead to installation, but the act of exploiting the vulnerability is categorized under Exploitation, not Installation.

  • ✗

    Reconnaissance

    Why it's wrong here

    Reconnaissance is the phase where the attacker gathers information about the target, such as email addresses, network ranges, and technologies in use. The scenario describes an active exploitation of a browser vulnerability, which occurs after reconnaissance. The attacker has already identified the target and is now executing the attack, so this phase does not apply.

  • ✓

    Exploitation

    Why this is correct

    Exploitation is the phase where the attacker leverages a vulnerability to gain access, such as exploiting a browser flaw when the user visits a malicious site. In this scenario, the malicious website exploits the browser vulnerability, which is the defining action of the Exploitation phase. This occurs after delivery and before installation of persistent malware.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.