112-52 · Question #99
In which phase of the hacking cycle does the hacker maintain access to use the network as a launch pad for other attacks?
The correct answer is A. Maintaining Access. Maintaining Access is correct because this phase is specifically where an attacker preserves their foothold in a compromised system - often installing backdoors, rootkits, or trojans - and leverages that access as a staging point to pivot into other systems or launch further atta
Question
In which phase of the hacking cycle does the hacker maintain access to use the network as a launch pad for other attacks?
Options
- AMaintaining Access
- BCovering Tracks
- CGaining Access
- DReconnaissance
How the community answered
(33 responses)- A88% (29)
- B3% (1)
- C3% (1)
- D6% (2)
Explanation
Maintaining Access is correct because this phase is specifically where an attacker preserves their foothold in a compromised system - often installing backdoors, rootkits, or trojans - and leverages that access as a staging point to pivot into other systems or launch further attacks.
- B (Covering Tracks) is wrong - that phase focuses on erasing evidence of intrusion (clearing logs, hiding files) to avoid detection, not on using the system offensively.
- C (Gaining Access) is wrong - that phase is about obtaining the initial foothold through exploits, password cracking, etc.; the attacker doesn't yet have stable, persistent control.
- D (Reconnaissance) is wrong - that's the earliest phase, involving passive or active information gathering before any intrusion occurs.
Memory tip: Think of the phases in order - Recon → Scanning → Gaining → Maintaining → Covering. "Maintaining" sits right before "Covering," so if the attacker is doing something useful with the system, they're in Maintaining; if they're cleaning up and leaving, they're in Covering.
Topics
Community Discussion
No community discussion yet for this question.