nerdexam
EC-Council

312-50V11 · Question #990

Josh has finished scanning a network and has discovered multiple vulnerable services. He knows that several of these usually have protections against external sources but are frequently susceptible…

The correct answer is D. Reconnaissance. Josh completed only the Reconnaissance stage by scanning the network and discovering vulnerable services; all subsequent activities were decisions or plans he had not yet executed.

Information Security and Ethical Hacking Fundamentals

Question

Josh has finished scanning a network and has discovered multiple vulnerable services. He knows that several of these usually have protections against external sources but are frequently susceptible to internal users. He decides to draft an email, spoof the sender as the internal IT team, and attach a malicious file disguised as a financial spreadsheet. Before Josh sends the email, he decides to investigate other methods of getting the file onto the system. For this particular attempt, what was the last stage of the cyber kill chain that Josh performed?

Options

  • AExploitation
  • BWeaponization
  • CDelivery
  • DReconnaissance

How the community answered

(26 responses)
  • A
    19% (5)
  • B
    4% (1)
  • C
    12% (3)
  • D
    65% (17)

Why each option

Josh completed only the Reconnaissance stage by scanning the network and discovering vulnerable services; all subsequent activities were decisions or plans he had not yet executed.

AExploitation

Exploitation occurs after a payload has been delivered and a vulnerability is actively leveraged on the target system; Josh has not yet sent or delivered any payload.

BWeaponization

Weaponization involves actually building and packaging a malicious payload; Josh only decided to draft the email and attachment but paused to investigate other methods before executing this stage.

CDelivery

Delivery is the stage where the weaponized payload is transmitted to the victim; Josh explicitly stopped before sending the email, so this stage was never performed.

DReconnaissanceCorrect

Reconnaissance is the information-gathering stage of the cyber kill chain and includes scanning the network and identifying vulnerable services, which Josh fully completed. His subsequent steps - drafting a phishing email and investigating other delivery methods - are described using the phrase 'decides to,' indicating planning intent rather than executed actions. Because no payload was created or delivered, Reconnaissance is the last stage Josh actually performed.

Concept tested: Cyber kill chain stage identification and sequencing

Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html

Topics

#cyber kill chain#reconnaissance#weaponization#attack stages

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice