Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

An analyst notices periodic HTTP GET requests to a suspicious domain every 60 seconds. The payload size is small and consistent. This behavior is characteristic of which phase of the Cyber Kill Chain?

⚠ Common exam trap

Watch out — candidates often confuse the C2 phase with Actions on Objectives because both involve network traffic; candidates must recognize that periodic, small beacons indicate ongoing control, not the final objective.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command and Control

Periodic, small, consistent HTTP GET requests to a suspicious external domain are the hallmark of beaconing, which occurs during the Command and Control (C2) phase of the Cyber Kill Chain. The compromised host is checking in with its C2 server at regular intervals to receive instructions or exfiltrate small amounts of data. This regular, low-volume traffic pattern is designed to blend in with normal traffic while maintaining persistent control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Actions on Objectives

    Why it's wrong here

    Actions on Objectives covers the attacker achieving their end goal, such as exfiltration or data destruction. Regular fixed-interval beaconing is command-and-control, not objective fulfilment. This phase would be correct if the analyst saw bulk data transfers, ransomware execution, or lateral movement toward target systems.

  • ✓

    Command and Control

    Why this is correct

    Regular, small, consistent beaconing to an external domain indicates an implanted host checking in with its controller. That recurring channel is the Command and Control phase, where the adversary maintains remote direction of compromised systems after exploitation.

  • ✗

    Delivery

    Why it's wrong here

    Delivery is the transmission of the weaponised payload to the victim, such as a phishing email or malicious download. The steady 60-second callback indicates an already-implanted beacon checking in, which is command-and-control. Delivery would be correct if the analyst saw the initial malicious file or link reaching the endpoint.

  • ✗

    Installation

    Why it's wrong here

    Installation covers establishing persistence on the compromised host, such as creating services or scheduled tasks. The beaconing pattern here is post-compromise command-and-control traffic, not host-resident persistence. Installation would be correct if the analyst observed new autorun registry entries or implanted backdoors surviving reboot.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.