312-50V12 · Question #203
In a recent cyber-attack against a large corporation, an unknown adversary compromised the network and began escalating privileges and lateral movement. The security team identified that the…
The correct answer is B. Analyzing the initial exploitation methods, the adversary used. The question asks for the most crucial initial analysis step after a cyber-attack involving zero-day exploitation. Analyzing the initial exploitation methods is paramount for understanding how the adversary gained entry.
Question
Options
- AIdentifying the specific tools used by the adversary for privilege escalation.
- BAnalyzing the initial exploitation methods, the adversary used.
- CChecking the persistence mechanisms used by the adversary in compromised systems.
- DInvestigating the data exfiltration methods used by the adversary.
How the community answered
(23 responses)- A4% (1)
- B61% (14)
- C9% (2)
- D26% (6)
Why each option
The question asks for the most crucial initial analysis step after a cyber-attack involving zero-day exploitation. Analyzing the initial exploitation methods is paramount for understanding how the adversary gained entry.
Identifying privilege escalation tools occurs after initial access has been gained, making it a subsequent step rather than the initial analysis of how the attack began.
Analyzing the initial exploitation methods is the most crucial first step in understanding any cyber-attack, especially when zero-day vulnerabilities are involved, as it identifies the root cause of the initial compromise. This foundational understanding is necessary to implement effective preventive measures and contain the breach.
Checking persistence mechanisms is typically performed after the initial breach and subsequent activities like privilege escalation, making it a later phase of attack analysis.
Investigating data exfiltration methods happens towards the end of a successful attack, after initial compromise, privilege escalation, and data collection, and thus is not part of the initial analysis.
Concept tested: Initial access and exploitation analysis in incident response
Source: https://attack.mitre.org/tactics/TA0001/
Topics
Community Discussion
No community discussion yet for this question.