200-201 · Question #249
A security engineer notices confidential data being exfiltrated to a domain 'Ransome4144- mware73-978' address that is attributed to a known advanced persistent threat group. The engineer discovers th
The correct answer is C. action on objectives. In this scenario, the attacker has already gained access to the victim's network and is exfiltrating confidential data to a known domain attributed to an advanced persistent threat group. Therefore, the attack has progressed beyond the initial stages of reconnaissance, weaponizat
Question
A security engineer notices confidential data being exfiltrated to a domain 'Ransome4144- mware73-978' address that is attributed to a known advanced persistent threat group. The engineer discovers that the activity is part of a real attack and not a network misconfiguration. Which category does this event fall under as defined in the Cyber Kill Chain?
Options
- Areconnaissance
- Bdelivery
- Caction on objectives
- Dweaponization
How the community answered
(24 responses)- A4% (1)
- C92% (22)
- D4% (1)
Explanation
In this scenario, the attacker has already gained access to the victim's network and is exfiltrating confidential data to a known domain attributed to an advanced persistent threat group. Therefore, the attack has progressed beyond the initial stages of reconnaissance, weaponization, delivery, and exploitation. The attacker has already achieved their objective, which is to exfiltrate sensitive
Topics
Community Discussion
No community discussion yet for this question.