200-201 · Question #223
The security team has detected an ongoing spam campaign targeting the organization. The team's approach is to push back the cyber kill chain and mitigate ongoing incidents. At which phase of the…
The correct answer is B. delivery. An ongoing spam campaign represents the delivery phase of the cyber kill chain, where the attacker attempts to transmit the malicious payload to the target.
Question
The security team has detected an ongoing spam campaign targeting the organization. The team's approach is to push back the cyber kill chain and mitigate ongoing incidents. At which phase of the cyber kill chain should the security team mitigate this type of attack?
Options
- Aactions
- Bdelivery
- Creconnaissance
- Dinstallation
How the community answered
(22 responses)- A5% (1)
- B73% (16)
- C5% (1)
- D18% (4)
Why each option
An ongoing spam campaign represents the delivery phase of the cyber kill chain, where the attacker attempts to transmit the malicious payload to the target.
The 'Actions on Objectives' phase occurs much later, after successful exploitation and installation, when the attacker achieves their ultimate goals.
A spam campaign is an attempt to deliver a weaponized payload (e.g., malicious links or attachments) to the target, which precisely aligns with the 'Delivery' phase of the cyber kill chain.
The 'Reconnaissance' phase involves gathering information about the target, which precedes the actual delivery of an attack.
The 'Installation' phase occurs after successful delivery and exploitation, when the attacker establishes persistent access to the victim's system.
Concept tested: Cyber kill chain - Delivery phase
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.