200-201 Network Intrusion Analysis Practice Question
An analyst is monitoring network traffic and observes a host making outbound HTTPS connections to a domain that appears to be generated by a Domain Generation Algorithm (DGA). Which phase of the Cyber Kill Chain best describes this activity?
⚠ Common exam trap
The trap is confusing the C2 callback with Installation or Actions on Objectives — candidates see 'malware' and pick Installation, or see 'HTTPS traffic' and pick Actions on Objectives, missing that the defining characteristic is the beaconing to attacker-controlled infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Command and Control (C2)
DGA-generated domains are used by malware to locate its C2 infrastructure, and the periodic HTTPS beaconing to those algorithmically generated domains is the hallmark of the Command and Control phase of the Cyber Kill Chain. The host has already been compromised and is now reaching out to receive instructions or exfiltrate data. This activity occurs after exploitation and installation but before the attacker achieves their final objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Installation
Why it's wrong here
Installation covers establishing persistence on the victim host, such as dropping a backdoor or service. The DGA beaconing here is command-and-control traffic, which sits in the Command and Control phase. Installation would be the answer if the stem described malware being placed and persisted on the compromised system.
- ✓
Command and Control (C2)
Why this is correct
DGA-generated domains are contacted by infected hosts to receive instructions from attacker infrastructure, which is the Command and Control phase. The outbound HTTPS beaconing to algorithmically generated domains is the defining C2 characteristic, occurring after exploitation and installation but before actions on objectives.
- ✗
Actions on Objectives
Why it's wrong here
Actions on Objectives is the final phase, where the attacker exfiltrates data, encrypts files for ransomware, or achieves the intrusion's goal. DGA lookups are beaconing to locate the C2 server, which is Command and Control. This option would fit if the stem showed data theft or destructive activity.
- ✗
Exploitation
Why it's wrong here
Exploitation delivers the payload that leverages a vulnerability to execute code on the target. The DGA domain resolution is post-compromise beaconing, placing it in Command and Control. Exploitation would be correct if the stem described a vulnerability being triggered, such as an exploit against a service.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.