200-201 Security Concepts Practice Question
A security analyst is reviewing an incident in which an attacker gained initial access to a corporate workstation by exploiting a vulnerability in a browser plugin. After gaining access, the attacker moved laterally to a file server and exfiltrated data. The analyst must map these activities to the cyber kill chain. Which phase of the kill chain does the browser plugin exploitation represent?
⚠ Common exam trap
It's easy for candidates to confuse weaponization with exploitation, because both involve preparing and using an exploit, but weaponization occurs before delivery while exploitation is the actual triggering of the vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploitation, because the attacker took advantage of the vulnerability to execute code on the workstation.
The browser plugin vulnerability was leveraged to gain code execution and initial access on the workstation. In the cyber kill chain, that action is exploitation, which follows reconnaissance and weaponization and precedes actions such as command and control, lateral movement, and exfiltration. The later lateral movement and data theft are separate phases, so the exploitation itself maps to the exploitation phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Command and control, because the attacker established a channel to manage the compromised host.
Why it's wrong here
Command and control is the phase where the attacker establishes a communication channel with compromised systems to issue commands and receive data. In this scenario, the question focuses on the browser plugin exploitation that granted initial access, not the later establishment of a management channel. While C2 likely followed, it is a distinct phase after exploitation.
- ✗
Weaponization, because the attacker prepared an exploit payload for the browser plugin.
Why it's wrong here
Weaponization is the phase where the attacker couples an exploit with a payload into a deliverable artifact, such as a malicious document or exploit kit component. It occurs before the exploit is delivered and triggered. The scenario describes the actual exploitation of the plugin on the workstation, which happens after weaponization, so this phase does not represent the exploitation event.
- ✗
Reconnaissance, because the attacker gathered information about the target before the attack.
Why it's wrong here
Reconnaissance is the information-gathering phase, such as scanning or OSINT collection, that occurs before an exploit is launched. In this scenario, the exploitation of the browser plugin is the actual delivery of the attack, not the preparatory research. While reconnaissance likely happened earlier, the question asks about the plugin exploitation itself, which is a later phase.
- ✓
Exploitation, because the attacker took advantage of the vulnerability to execute code on the workstation.
Why this is correct
Exploitation is the kill chain phase where the attacker leverages a vulnerability to execute code or gain access. Exploiting the browser plugin vulnerability to gain initial access on the workstation is precisely this phase. The subsequent lateral movement and exfiltration are later phases, but the plugin exploitation itself maps to exploitation, making this the correct mapping.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.