312-50V12 · Question #81
At what stage of the cyber kill chain theory model does data exfiltration occur?
The correct answer is B. Actions on objectives. The Cyber Kill Chain model defines seven stages of an attack, with data exfiltration occurring in the final 'Actions on Objectives' phase after the attacker has achieved full access.
Question
Options
- AWeaponization
- BActions on objectives
- CCommand and control
- DInstallation
How the community answered
(36 responses)- A6% (2)
- B92% (33)
- D3% (1)
Why each option
The Cyber Kill Chain model defines seven stages of an attack, with data exfiltration occurring in the final 'Actions on Objectives' phase after the attacker has achieved full access.
Weaponization is the second stage where the attacker creates a deliverable malicious payload (e.g., coupling an exploit with a backdoor), which happens before any intrusion into the target network.
Actions on Objectives is the final stage of the Cyber Kill Chain where the attacker achieves their ultimate goal, which may include data exfiltration, destruction, encryption for ransom, or lateral movement. This stage occurs only after all prior stages have been completed, meaning the attacker has established a foothold, escalated privileges, and maintained persistence within the target environment.
Command and Control (C2) is the stage where the attacker establishes a remote communication channel to the compromised system, enabling ongoing control, but data exfiltration has not yet occurred at this point.
Installation refers to the stage where the attacker installs a persistent backdoor or remote access tool on the victim's system to maintain long-term access, which precedes the execution of the attacker's final objectives.
Concept tested: Cyber Kill Chain stages and data exfiltration phase
Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html
Topics
Community Discussion
No community discussion yet for this question.