200-201 Network Intrusion Analysis Practice Question
An analyst notices periodic HTTP GET requests to a suspicious domain every 60 seconds. The payload size is small and consistent. This behavior is characteristic of which phase of the Cyber Kill Chain?
⚠ Common exam trap
Watch out — candidates often confuse the C2 phase with Actions on Objectives because both involve network traffic; candidates must recognize that periodic, small beacons indicate ongoing control, not the final objective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Command and Control
Periodic, small, consistent HTTP GET requests to a suspicious external domain are the hallmark of beaconing, which occurs during the Command and Control (C2) phase of the Cyber Kill Chain. The compromised host is checking in with its C2 server at regular intervals to receive instructions or exfiltrate small amounts of data. This regular, low-volume traffic pattern is designed to blend in with normal traffic while maintaining persistent control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Actions on Objectives
Why it's wrong here
Actions on Objectives covers the attacker achieving their end goal, such as exfiltration or data destruction. Regular fixed-interval beaconing is command-and-control, not objective fulfilment. This phase would be correct if the analyst saw bulk data transfers, ransomware execution, or lateral movement toward target systems.
- ✓
Command and Control
Why this is correct
Regular, small, consistent beaconing to an external domain indicates an implanted host checking in with its controller. That recurring channel is the Command and Control phase, where the adversary maintains remote direction of compromised systems after exploitation.
- ✗
Delivery
Why it's wrong here
Delivery is the transmission of the weaponised payload to the victim, such as a phishing email or malicious download. The steady 60-second callback indicates an already-implanted beacon checking in, which is command-and-control. Delivery would be correct if the analyst saw the initial malicious file or link reaching the endpoint.
- ✗
Installation
Why it's wrong here
Installation covers establishing persistence on the compromised host, such as creating services or scheduled tasks. The beaconing pattern here is post-compromise command-and-control traffic, not host-resident persistence. Installation would be correct if the analyst observed new autorun registry entries or implanted backdoors surviving reboot.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.