200-201 · Question #399
During a quarterly vulnerability scan, a security analyst discovered unused uncommon ports open and in a listening state. Further investigation showed that the unknown application was communicating…
The correct answer is B. Actions on Objectives. The detection of command and control communication on an infected server, along with unused open ports and encrypted external communication, indicates the attacker is in the 'Actions on Objectives' phase, having already established a foothold and performing post-exploitation…
Question
During a quarterly vulnerability scan, a security analyst discovered unused uncommon ports open and in a listening state. Further investigation showed that the unknown application was communicating with an external IP address on an encrypted channel. A deeper analysis revealed a command and control communication on an infected server. At which step of the Cyber Kill Chain was the attack detected?
Options
- AExploitation
- BActions on Objectives
- CWeaponization
- DDelivery
How the community answered
(55 responses)- A15% (8)
- B73% (40)
- C4% (2)
- D9% (5)
Why each option
The detection of command and control communication on an infected server, along with unused open ports and encrypted external communication, indicates the attacker is in the 'Actions on Objectives' phase, having already established a foothold and performing post-exploitation activities.
Exploitation is the step where the attacker successfully breaches a vulnerability to gain access, but the C2 communication indicates a phase after initial exploitation.
The discovery of command and control (C2) communication on an infected server signifies that the attacker has successfully gained access (exploitation), established a persistent presence (installation), and is now communicating with their remote infrastructure to achieve their ultimate goals. This activity falls under the 'Actions on Objectives' phase of the Cyber Kill Chain, where the attacker executes commands to achieve their ultimate mission, such as data exfiltration or further compromise.
Weaponization is the phase where the attacker bundles an exploit with a backdoor into a deliverable payload, which occurs before delivery and exploitation.
Delivery is the phase where the weaponized payload is transmitted to the victim, occurring before exploitation and C2 communication.
Concept tested: Cyber Kill Chain phases - Actions on Objectives
Source: https://www.microsoft.com/en-us/security/business/security-intelligence/what-is-cyber-kill-chain
Topics
Community Discussion
No community discussion yet for this question.