Option C makes sense since exploitation is literally when the attacker takes advantage of a vulnerability. The other phases are about delivery, persistence or objectives, not the actual attack step. I think that's spot on but I'm open if anyone disagrees.
A network administrator is investigating suspicious network activity by analyzing captured traffic. An
engineer notices abnormal behavior and discovers that the default user agent is present in the
headers of requests and data being transmitted What is occurring?CVSS makes the attack vector score higher when a vulnerability can be exploited remotely. So C fits with what I remember from similar exam questions, but if I'm off let me know.
Had something like this in a mock before, it's C. Digital certificates are needed for decryption on perimeter devices so they can scan the traffic. Pretty straightforward if you're familiar with SSL/TLS inspection. Let me know if anyone picked differently.
Official Cisco guides cover how digital certificates enable decryption for inspecting encrypted traffic. Practice labs are helpful to see how this lets network security devices catch command-and-control stuff. Pretty sure C is right, but open for discussion.
DRAG DROP Refer to the exhibit. 

