200-201 · Question #188
A user received an email attachment named "Hr405-report2609-empl094.exe" but did not run it. Which category of the cyber kill chain should be assigned to this type of event?
The correct answer is D. delivery. The event where a user received a malicious email attachment but did not run it falls under the 'Delivery' phase of the cyber kill chain.
Question
A user received an email attachment named "Hr405-report2609-empl094.exe" but did not run it. Which category of the cyber kill chain should be assigned to this type of event?
Options
- Ainstallation
- Breconnaissance
- Cweaponization
- Ddelivery
How the community answered
(32 responses)- A3% (1)
- C6% (2)
- D91% (29)
Why each option
The event where a user received a malicious email attachment but did not run it falls under the 'Delivery' phase of the cyber kill chain.
The 'Installation' phase occurs after successful exploitation, when the attacker establishes persistence on the target system, which did not happen here as the file was not run.
The 'Reconnaissance' phase involves gathering information about the target, which happens before the delivery of a payload.
The 'Weaponization' phase involves combining an exploit with a payload into a deliverable package, which occurs before the delivery to the victim.
In the cyber kill chain, the 'Delivery' phase involves transmitting the weaponized artifact (the malicious executable attachment) to the target. Receiving the email attachment completes this phase, regardless of whether it was executed.
Concept tested: Cyber Kill Chain - Delivery phase
Source: https://learn.microsoft.com/en-us/azure/sentinel/fusion-detection
Topics
Community Discussion
No community discussion yet for this question.