Courseiva
Security Concepts →hardMultiple Choice

200-201 Security Concepts Practice Question

A security operations center (SOC) analyst is investigating a security incident where an attacker gained initial access to a corporate network. The analyst suspects the attacker used a technique that involves exploiting a vulnerability in a public-facing web server to execute arbitrary code. Which phase of the Cyber Kill Chain does this activity represent?

⚠ Common exam trap

The trap here is conflating exploitation with installation, as both involve code execution, but exploitation is about gaining initial access, while installation is about maintaining persistence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploitation

The Cyber Kill Chain phase of exploitation involves taking advantage of a vulnerability to execute code on a target system. The scenario describes an attacker exploiting a web server vulnerability to run arbitrary code, which fits the exploitation phase. Reconnaissance and weaponization are preparatory, while installation is a later step for maintaining access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Weaponization

    Why it's wrong here

    Weaponization is the phase where the attacker creates a deliverable payload, such as a malicious document or exploit code, often combining malware with an exploit. It occurs before delivery and does not involve interaction with the target network. The scenario describes an active exploitation on a web server, not the preparation of the tool.

  • ✗

    Installation

    Why it's wrong here

    Installation is the phase where the attacker installs malware or a backdoor to maintain persistence on the compromised system. While code execution might lead to installation, the scenario specifically describes the initial exploitation of a vulnerability, not the subsequent installation of persistent tools. The analyst is investigating the initial access method, which is exploitation.

  • ✓

    Exploitation

    Why this is correct

    Exploitation is the phase where the attacker leverages a vulnerability to gain access to the target system. In this scenario, the attacker exploits a vulnerability in a public-facing web server to execute arbitrary code, which is a classic example of exploitation. This phase directly follows delivery and precedes installation of persistent access.

  • ✗

    Reconnaissance

    Why it's wrong here

    Reconnaissance involves the attacker gathering information about the target, such as scanning for open ports or researching employees. In this scenario, the attacker has already exploited a vulnerability and executed code, which is a later phase. Reconnaissance precedes the actual attack and does not involve code execution on the target.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.