200-201 Security Concepts Practice Question
A security analyst is investigating an incident where an attacker gained initial access to a corporate network. The analyst finds that the attacker sent a phishing email with a link to a malicious website that exploited a vulnerability in the user's browser. Which phase of the Cyber Kill Chain does the browser exploitation represent?
⚠ Common exam trap
Watch out — candidates often confuse Delivery with Exploitation, but the delivery is the phishing email, while the actual vulnerability exploitation is the browser compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploitation
The Cyber Kill Chain phases are Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives. When a user visits a malicious website that exploits a browser vulnerability, that action is Exploitation. It follows Delivery (the phishing email with the link) and precedes Installation of any persistent payload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Weaponization
Why it's wrong here
Weaponization involves creating or preparing the malicious payload, such as coupling an exploit with a deliverable like a malicious document or website. The scenario describes the actual exploitation occurring on the user's browser, which happens after weaponization. The weapon has already been delivered and is now being used, so this is not the correct phase.
- ✗
Installation
Why it's wrong here
Installation is the phase where the attacker establishes persistence on the victim's system, such as installing a backdoor or remote access trojan. The scenario describes the browser exploitation itself, which precedes any installation. The exploit may lead to installation, but the act of exploiting the vulnerability is categorized under Exploitation, not Installation.
- ✗
Reconnaissance
Why it's wrong here
Reconnaissance is the phase where the attacker gathers information about the target, such as email addresses, network ranges, and technologies in use. The scenario describes an active exploitation of a browser vulnerability, which occurs after reconnaissance. The attacker has already identified the target and is now executing the attack, so this phase does not apply.
- ✓
Exploitation
Why this is correct
Exploitation is the phase where the attacker leverages a vulnerability to gain access, such as exploiting a browser flaw when the user visits a malicious site. In this scenario, the malicious website exploits the browser vulnerability, which is the defining action of the Exploitation phase. This occurs after delivery and before installation of persistent malware.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.