200-201 · Question #34
A user received a malicious attachment but did not run it. Which category classifies the intrusion?
The correct answer is D. delivery. If a user receives a malicious attachment but does not execute it, the intrusion has reached the delivery stage of the Cyber Kill Chain.
Question
A user received a malicious attachment but did not run it. Which category classifies the intrusion?
Options
- Aweaponization
- Breconnaissance
- Cinstallation
- Ddelivery
How the community answered
(31 responses)- B3% (1)
- C3% (1)
- D94% (29)
Why each option
If a user receives a malicious attachment but does not execute it, the intrusion has reached the delivery stage of the Cyber Kill Chain.
Weaponization is the stage where the attacker combines an exploit and a backdoor into a deliverable payload, occurring before delivery.
Reconnaissance is the initial stage where an attacker gathers information about the target, which happens long before a malicious attachment is sent.
Installation refers to the stage where the attacker installs persistent access to the victim's system, which requires the malicious attachment to be executed, which did not occur here.
Delivery is the stage in the Cyber Kill Chain where the attacker transmits the weaponized malware to the victim, such as via an email attachment, signifying successful delivery even if not executed.
Concept tested: Cyber Kill Chain - Delivery Stage
Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html
Topics
Community Discussion
No community discussion yet for this question.