nerdexam
EC-Council

312-50V12 · Question #232

A cyber attacker has initiated a series of activities against a high-profile organization following the Cyber Kill Chain Methodology. The attacker is presently in the "Delivery" stage. As an Ethical…

The correct answer is B. The attacker will exploit the malicious payload delivered to the target organization and establish a. Following the Cyber Kill Chain Methodology, the stage immediately after "Delivery" is "Exploitation," where the attacker activates the delivered payload. Therefore, the most probable next action is exploiting the malicious payload.

Submitted by skyler.x· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

A cyber attacker has initiated a series of activities against a high-profile organization following the Cyber Kill Chain Methodology. The attacker is presently in the "Delivery" stage. As an Ethical Hacker, you are trying to anticipate the adversary's next move. What is the most probable subsequent action from the attacker based on the Cyber Kill Chain Methodology?

Options

  • AThe attacker will attempt to escalate privileges to gain complete control of the compromised
  • BThe attacker will exploit the malicious payload delivered to the target organization and establish a
  • CThe attacker will initiate an active connection to the target system to gather more data.
  • DThe attacker will start reconnaissance to gather as much information as possible about the target.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    87% (27)
  • C
    6% (2)
  • D
    3% (1)

Why each option

Following the Cyber Kill Chain Methodology, the stage immediately after "Delivery" is "Exploitation," where the attacker activates the delivered payload. Therefore, the most probable next action is exploiting the malicious payload.

AThe attacker will attempt to escalate privileges to gain complete control of the compromised

Privilege escalation is typically a post-exploitation activity, occurring after initial access has been gained and a system is compromised, falling under stages like "Installation" or "Actions on Objectives."

BThe attacker will exploit the malicious payload delivered to the target organization and establish aCorrect

After a malicious payload has been successfully delivered to a target system, the next logical step in the Cyber Kill Chain is "Exploitation." This involves the attacker triggering the vulnerability the payload is designed to exploit, executing the malicious code, and gaining initial access or establishing a foothold within the target's environment.

CThe attacker will initiate an active connection to the target system to gather more data.

Initiating an active connection to gather more data often describes activities within the "Command and Control" stage or ongoing reconnaissance, which occurs after exploitation and installation.

DThe attacker will start reconnaissance to gather as much information as possible about the target.

Reconnaissance is the initial stage of the Cyber Kill Chain, occurring long before the "Delivery" stage to gather information about the target.

Concept tested: Cyber Kill Chain Methodology stages

Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html

Topics

#Cyber Kill Chain#Delivery stage#Exploitation#Attack phases

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice