200-201 · Question #155
The SOC team detected an ongoing port scan. After investigation, the team concluded that the scan was targeting the company servers. According to the Cyber Kill Chain model, which step must be…
The correct answer is C. reconnaissance. An ongoing port scan is an information-gathering activity where an attacker probes a target's network to identify open ports and services, which aligns with the reconnaissance phase of the Cyber Kill Chain.
Question
The SOC team detected an ongoing port scan. After investigation, the team concluded that the scan was targeting the company servers. According to the Cyber Kill Chain model, which step must be assigned to this type of event?
Options
- Adelivery
- Bexploitation
- Creconnaissance
- Dactions on objectives
How the community answered
(22 responses)- A5% (1)
- B9% (2)
- C86% (19)
Why each option
An ongoing port scan is an information-gathering activity where an attacker probes a target's network to identify open ports and services, which aligns with the reconnaissance phase of the Cyber Kill Chain.
Delivery involves the transmission of the weaponized payload to the target, which happens after reconnaissance and weaponization.
Exploitation occurs when the attacker triggers a vulnerability to gain access to the system, which happens after reconnaissance and delivery.
Reconnaissance is the initial phase of the Cyber Kill Chain where adversaries gather information about their target before launching an attack. A port scan directly falls into this category as it's used to discover active services, open ports, and potential vulnerabilities on the company's servers.
Actions on objectives refer to the final steps an attacker takes once they have access, such as data exfiltration, destruction, or achieving their mission goals, which is far beyond a port scan.
Concept tested: Cyber Kill Chain - Reconnaissance phase
Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html
Topics
Community Discussion
No community discussion yet for this question.