nerdexam
EC-Council

212-82 · Question #124

An advanced persistent threat (APT) group known for Its stealth and sophistication targeted a leading software development company. The attack was meticulously planned and executed over several…

The correct answer is B. Exploiting a zero-day vulnerability in the application used by developers. The description of "exploitation of unknown/unpatched vulnerabilities in software/hardware" by a sophisticated APT group strongly suggests the use of zero-day vulnerabilities for initial access.

Submitted by tunde_lagos· Mar 6, 2026Cloud Security Risks & Threat Mitigation

Question

An advanced persistent threat (APT) group known for Its stealth and sophistication targeted a leading software development company. The attack was meticulously planned and executed over several months. It involved exploiting vulnerabilities at both the application level and the operating system level. The attack resulted in the extraction of sensitive source code and disruption of development operations. Post-incident analysis revealed multiple attack vectors, including phishing, exploitation of unknown/unpatched vulnerabilities in software/hardware. and lateral movement within the network. Given the nature and execution of this attack, what was the primary method used by the attackers to initiate this APT?

Options

  • AExploiting default passwords to gain initial access to the network.
  • BExploiting a zero-day vulnerability in the application used by developers.
  • CExploiting a known vulnerability in the firewall to bypass network defenses.
  • DCompromising a third-party vendor with access to the company's development environment.

How the community answered

(52 responses)
  • A
    12% (6)
  • B
    58% (30)
  • C
    6% (3)
  • D
    25% (13)

Why each option

The description of "exploitation of unknown/unpatched vulnerabilities in software/hardware" by a sophisticated APT group strongly suggests the use of zero-day vulnerabilities for initial access.

AExploiting default passwords to gain initial access to the network.

Exploiting default passwords is a common and simple attack method, but less indicative of the "stealth and sophistication" of a meticulously planned, multi-month APT involving "unknown/unpatched vulnerabilities."

BExploiting a zero-day vulnerability in the application used by developers.Correct

The scenario explicitly mentions "exploitation of unknown/unpatched vulnerabilities in software/hardware" by an APT group known for stealth and sophistication. "Unknown/unpatched vulnerabilities" is a direct description of zero-day vulnerabilities, which are highly favored by APTs for initial access due to their ability to bypass traditional defenses.

CExploiting a known vulnerability in the firewall to bypass network defenses.

While exploiting known vulnerabilities can occur, the scenario specifically refers to "unknown/unpatched vulnerabilities," making a known vulnerability in the firewall less likely as the primary initial method described for this type of attack.

DCompromising a third-party vendor with access to the company's development environment.

Compromising a third-party vendor is a possible APT vector, but the question explicitly states "exploitation of unknown/unpatched vulnerabilities in software/hardware" as one of the vectors, leading directly to the zero-day concept.

Concept tested: Advanced Persistent Threat (APT) initial access methods and zero-day exploitation

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/zero-day-exploit?view=o365-worldwide

Topics

#APT#Zero-day vulnerability#Attack vectors#Application exploits

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice