312-50V12 · Question #232
A cyber attacker has initiated a series of activities against a high-profile organization following the Cyber Kill Chain Methodology. The attacker is presently in the "Delivery" stage. As an Ethical…
The correct answer is B. The attacker will exploit the malicious payload delivered to the target organization and establish a. Following the Cyber Kill Chain Methodology, the stage immediately after "Delivery" is "Exploitation," where the attacker activates the delivered payload. Therefore, the most probable next action is exploiting the malicious payload.
Question
Options
- AThe attacker will attempt to escalate privileges to gain complete control of the compromised
- BThe attacker will exploit the malicious payload delivered to the target organization and establish a
- CThe attacker will initiate an active connection to the target system to gather more data.
- DThe attacker will start reconnaissance to gather as much information as possible about the target.
How the community answered
(31 responses)- A3% (1)
- B87% (27)
- C6% (2)
- D3% (1)
Why each option
Following the Cyber Kill Chain Methodology, the stage immediately after "Delivery" is "Exploitation," where the attacker activates the delivered payload. Therefore, the most probable next action is exploiting the malicious payload.
Privilege escalation is typically a post-exploitation activity, occurring after initial access has been gained and a system is compromised, falling under stages like "Installation" or "Actions on Objectives."
After a malicious payload has been successfully delivered to a target system, the next logical step in the Cyber Kill Chain is "Exploitation." This involves the attacker triggering the vulnerability the payload is designed to exploit, executing the malicious code, and gaining initial access or establishing a foothold within the target's environment.
Initiating an active connection to gather more data often describes activities within the "Command and Control" stage or ongoing reconnaissance, which occurs after exploitation and installation.
Reconnaissance is the initial stage of the Cyber Kill Chain, occurring long before the "Delivery" stage to gather information about the target.
Concept tested: Cyber Kill Chain Methodology stages
Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html
Topics
Community Discussion
No community discussion yet for this question.