Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

An analyst is monitoring network traffic and observes a host making outbound HTTPS connections to a domain that appears to be generated by a Domain Generation Algorithm (DGA). Which phase of the Cyber Kill Chain best describes this activity?

⚠ Common exam trap

The trap is confusing the C2 callback with Installation or Actions on Objectives — candidates see 'malware' and pick Installation, or see 'HTTPS traffic' and pick Actions on Objectives, missing that the defining characteristic is the beaconing to attacker-controlled infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command and Control (C2)

DGA-generated domains are used by malware to locate its C2 infrastructure, and the periodic HTTPS beaconing to those algorithmically generated domains is the hallmark of the Command and Control phase of the Cyber Kill Chain. The host has already been compromised and is now reaching out to receive instructions or exfiltrate data. This activity occurs after exploitation and installation but before the attacker achieves their final objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Installation

    Why it's wrong here

    Installation covers establishing persistence on the victim host, such as dropping a backdoor or service. The DGA beaconing here is command-and-control traffic, which sits in the Command and Control phase. Installation would be the answer if the stem described malware being placed and persisted on the compromised system.

  • ✓

    Command and Control (C2)

    Why this is correct

    DGA-generated domains are contacted by infected hosts to receive instructions from attacker infrastructure, which is the Command and Control phase. The outbound HTTPS beaconing to algorithmically generated domains is the defining C2 characteristic, occurring after exploitation and installation but before actions on objectives.

  • ✗

    Actions on Objectives

    Why it's wrong here

    Actions on Objectives is the final phase, where the attacker exfiltrates data, encrypts files for ransomware, or achieves the intrusion's goal. DGA lookups are beaconing to locate the C2 server, which is Command and Control. This option would fit if the stem showed data theft or destructive activity.

  • ✗

    Exploitation

    Why it's wrong here

    Exploitation delivers the payload that leverages a vulnerability to execute code on the target. The DGA domain resolution is post-compromise beaconing, placing it in Command and Control. Exploitation would be correct if the stem described a vulnerability being triggered, such as an exploit against a service.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.