200-201 · Question #331
A cyberattacker notices a security flaw in a software that a company is using. They decide to tailor a specific worm to exploit this flaw and extract saved passwords from the software. To which…
The correct answer is A. weaponization. This event belongs to the 'weaponization' stage of the Cyber Kill Chain model, as the attacker is combining an exploit with a payload to create a specific worm.
Question
A cyberattacker notices a security flaw in a software that a company is using. They decide to tailor a specific worm to exploit this flaw and extract saved passwords from the software. To which category of the Cyber Kill Chain model does this event belong?
Options
- Aweaponization
- Breconnaissance
- Cdelivery
- Dexploitation
How the community answered
(36 responses)- A72% (26)
- B3% (1)
- C8% (3)
- D17% (6)
Why each option
This event belongs to the 'weaponization' stage of the Cyber Kill Chain model, as the attacker is combining an exploit with a payload to create a specific worm.
Weaponization is the stage where the attacker combines an exploit (the tailored worm designed to leverage the security flaw) with a malicious payload (to extract passwords) into a deliverable package. This combination creates the weapon that will be used to achieve the attacker's objectives.
Reconnaissance is the stage where the attacker gathers information about the target, such as identifying the software flaw, but does not involve creating the attack tool itself.
Delivery is the stage where the weaponized artifact is transmitted to the target, such as via email or a compromised website, not the creation of the artifact.
Exploitation is the stage where the weaponized artifact successfully executes and leverages the vulnerability to gain access, occurring after the weapon has been delivered.
Concept tested: Cyber Kill Chain stages (Weaponization)
Source: https://www.microsoft.com/en-us/security/business/security-101/what-is-cyber-kill-chain
Topics
Community Discussion
No community discussion yet for this question.