312-50V12 · Question #17
Infecting a system with malware and using phishing to gain credentials to a system or web application are examples of which phase of the ethical hacking methodology?
The correct answer is B. Gaining access. Gaining Access – Explained Option B is correct because the "gaining access" phase is specifically where an attacker actively exploits vulnerabilities to enter a system - this includes deploying malware, using phishing to steal credentials, exploiting software flaws, or cracking…
Question
Options
- AScanning
- BGaining access
- CMaintaining access
- DReconnaissance
How the community answered
(30 responses)- A3% (1)
- B87% (26)
- C7% (2)
- D3% (1)
Explanation
Gaining Access – Explained
Option B is correct because the "gaining access" phase is specifically where an attacker actively exploits vulnerabilities to enter a system - this includes deploying malware, using phishing to steal credentials, exploiting software flaws, or cracking passwords to achieve unauthorized entry.
Why the distractors are wrong:
- A (Scanning) involves passively or actively probing the target to discover open ports, services, and vulnerabilities - finding weaknesses, not exploiting them
- D (Reconnaissance) is even earlier, focused on gathering information about the target (e.g., OSINT, footprinting) without directly interacting with systems
- C (Maintaining access) comes after entry has already been achieved, involving backdoors, rootkits, or persistence mechanisms to keep the attacker in the system
Memory Tip: Think of the phases in logical order - Recon → Scan → Gain → Maintain → Cover Tracks. Ask yourself: "Has the attacker gotten IN yet?" Phishing and malware are the tools used to get in, making them clearly part of the gaining access phase.
Topics
Community Discussion
No community discussion yet for this question.