312-50V13 · Question #214
At what stage of the cyber kill chain theory model does data exfiltration occur?
The correct answer is A. Actions on objectives. Cyber Kill Chain: Data Exfiltration Stage Actions on Objectives (A) is correct because this is the final stage of the Lockheed Martin Cyber Kill Chain, where the attacker achieves their ultimate goal - which commonly includes stealing sensitive data (exfiltration), destroying…
Question
Options
- AActions on objectives
- BWeaponization
- Cinstallation
- DCommand and control
How the community answered
(28 responses)- A93% (26)
- B4% (1)
- D4% (1)
Explanation
Cyber Kill Chain: Data Exfiltration Stage
Actions on Objectives (A) is correct because this is the final stage of the Lockheed Martin Cyber Kill Chain, where the attacker achieves their ultimate goal - which commonly includes stealing sensitive data (exfiltration), destroying files, or encrypting systems for ransom. By this stage, the attacker has full access and executes their intended mission.
Weaponization (B) is wrong because this is an early preparation stage where the attacker creates a malicious payload (e.g., embedding malware into a document) - no target system has even been touched yet. Installation (C) is incorrect because this stage involves establishing a persistent foothold (e.g., installing a backdoor) on the compromised system, not yet stealing data. Command and Control (D) is wrong because this stage focuses on establishing a remote communication channel between the attacker and the compromised system - a precursor to taking action, not the action itself.
Memory Tip: Think of "Actions on Objectives" as the finish line - everything before it (delivery, exploitation, installation, C2) is just setup. If the goal is stealing data, that theft happens at the very end, when the attacker finally acts on why they broke in.
Topics
Community Discussion
No community discussion yet for this question.