nerdexam
EC-Council

312-50V12 · Question #17

Infecting a system with malware and using phishing to gain credentials to a system or web application are examples of which phase of the ethical hacking methodology?

The correct answer is B. Gaining access. Gaining Access – Explained Option B is correct because the "gaining access" phase is specifically where an attacker actively exploits vulnerabilities to enter a system - this includes deploying malware, using phishing to steal credentials, exploiting software flaws, or cracking…

Submitted by tunde_lagos· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

Infecting a system with malware and using phishing to gain credentials to a system or web application are examples of which phase of the ethical hacking methodology?

Options

  • AScanning
  • BGaining access
  • CMaintaining access
  • DReconnaissance

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    87% (26)
  • C
    7% (2)
  • D
    3% (1)

Explanation

Gaining Access – Explained

Option B is correct because the "gaining access" phase is specifically where an attacker actively exploits vulnerabilities to enter a system - this includes deploying malware, using phishing to steal credentials, exploiting software flaws, or cracking passwords to achieve unauthorized entry.

Why the distractors are wrong:

  • A (Scanning) involves passively or actively probing the target to discover open ports, services, and vulnerabilities - finding weaknesses, not exploiting them
  • D (Reconnaissance) is even earlier, focused on gathering information about the target (e.g., OSINT, footprinting) without directly interacting with systems
  • C (Maintaining access) comes after entry has already been achieved, involving backdoors, rootkits, or persistence mechanisms to keep the attacker in the system

Memory Tip: Think of the phases in logical order - Recon → Scan → Gain → Maintain → Cover Tracks. Ask yourself: "Has the attacker gotten IN yet?" Phishing and malware are the tools used to get in, making them clearly part of the gaining access phase.

Topics

#Ethical Hacking Methodology#Gaining Access#Malware#Phishing

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice