200-201 · Question #170
Drag and Drop Question Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model. Answer:
The correct answer is The targeted environment is taken advantage of triggering the threat actor's code.; Backdoor is placed on the victim system allowing the threat actor to maintain the persistence.; An outbound connection is established to an Internet-based controller server.; The threat actor takes actions to violate data integrity and availability. The Cyber Kill Chain model defines sequential phases of a cyberattack. 'Exploitation' is where the targeted environment is taken advantage of to trigger the threat actor's code. 'Installation' follows, where a backdoor is placed on the victim system for persistence. 'Command &…
Question
Drag and Drop Question Drag and drop the definition from the left onto the phase on the right to classify intrusion events according to the Cyber Kill Chain model. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- The targeted environment is taken advantage of triggering the threat actor's code.
- Backdoor is placed on the victim system allowing the threat actor to maintain the persistence.
- An outbound connection is established to an Internet-based controller server.
- The threat actor takes actions to violate data integrity and availability.
Explanation
The Cyber Kill Chain model defines sequential phases of a cyberattack. 'Exploitation' is where the targeted environment is taken advantage of to trigger the threat actor's code. 'Installation' follows, where a backdoor is placed on the victim system for persistence. 'Command & Control (C2)' involves establishing an outbound connection to an internet-based controller server, and 'Actions on Objectives' is the final phase where the threat actor violates data integrity and availability to achieve their goals.
Topics
Community Discussion
No community discussion yet for this question.
