nerdexam
EC-Council

312-50V12 · Question #124

Harry, a professional hacker, targets the IT infrastructure of an organization. After preparing for the attack, he attempts to enter the target network using techniques such as sending spear…

The correct answer is A. Initial intrusion. APT Lifecycle Phase Explanation Option A is correct because Harry is actively breaching the target network for the first time using spear-phishing emails and exploiting public-facing server vulnerabilities to deploy malware - this defines the Initial Intrusion phase, where the…

Submitted by klara.se· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

Harry, a professional hacker, targets the IT infrastructure of an organization. After preparing for the attack, he attempts to enter the target network using techniques such as sending spear- phishing emails and exploiting vulnerabilities on publicly available servers. Using these techniques, he successfully deployed malware on the target system to establish an outbound connection. What is the APT lifecycle phase that Harry is currently executing?

Options

  • AInitial intrusion
  • BPersistence
  • CCleanup
  • DPreparation

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    4% (1)
  • C
    18% (5)
  • D
    7% (2)

Explanation

APT Lifecycle Phase Explanation

Option A is correct because Harry is actively breaching the target network for the first time using spear-phishing emails and exploiting public-facing server vulnerabilities to deploy malware - this defines the Initial Intrusion phase, where the attacker gains their first foothold into the target environment.

The distractors are wrong because: Preparation (D) occurs before the attack and involves reconnaissance, acquiring tools, and planning - Harry has already completed this stage; Persistence (B) comes after initial intrusion, where the attacker works to maintain long-term, undetected access to the compromised system; Cleanup (C) is the final phase, where attackers remove traces of their activity to avoid detection after completing their objectives.

Memory Tip: Think of APT phases like breaking into a building - Preparation = planning the heist, Initial Intrusion = picking the lock to get inside for the first time, Persistence = hiding inside so you can stay, and Cleanup = wiping your fingerprints on the way out. The key trigger word in the question is "attempts to enter" - "entering" always signals Initial Intrusion.

Topics

#APT lifecycle#Initial intrusion#Gaining access#Vulnerability exploitation

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice