nerdexam
EC-Council

312-50V13 · Question #244

Harry. a professional hacker, targets the IT infrastructure of an organization. After preparing for the attack, he attempts to enter the target network using techniques such as sending spear…

The correct answer is D. Initial Intrusion. APT Lifecycle Phase Explanation Option D (Initial Intrusion) is correct because Harry is actively breaching the target network for the first time using attack vectors like spear-phishing emails and exploiting public-facing server vulnerabilities - this is the defining…

Submitted by zhang_li· Mar 6, 2026System Hacking

Question

Harry. a professional hacker, targets the IT infrastructure of an organization. After preparing for the attack, he attempts to enter the target network using techniques such as sending spear- phishing emails and exploiting vulnerabilities on publicly available servers. Using these techniques, he successfully deployed malware on the target system to establish an outbound connection. What is the APT lifecycle phase that Harry is currently executing?

Options

  • APreparation
  • BCleanup
  • CPersistence
  • DInitial Intrusion

How the community answered

(55 responses)
  • A
    11% (6)
  • B
    5% (3)
  • C
    4% (2)
  • D
    80% (44)

Explanation

APT Lifecycle Phase Explanation

Option D (Initial Intrusion) is correct because Harry is actively breaching the target network for the first time using attack vectors like spear-phishing emails and exploiting public-facing server vulnerabilities - this is the defining characteristic of the Initial Intrusion phase, where the attacker gains their first foothold by deploying malware to establish an outbound (C2) connection.

Why the distractors are wrong:

  • A (Preparation) occurs before the attack begins - it involves reconnaissance, building tools, and selecting targets, which Harry has already completed
  • C (Persistence) comes after initial intrusion, when the attacker works to maintain long-term access to the compromised system
  • B (Cleanup) is the final phase, where attackers remove traces of their activity to avoid detection after achieving their objectives

Memory Tip: Think of the APT lifecycle as a burglary analogy - Preparation = casing the building, Initial Intrusion = breaking through the front door, Persistence = hiding inside, and Cleanup = wiping fingerprints. Whenever you see first entry methods like phishing or exploiting public servers, that's your signal for Initial Intrusion.

Topics

#APT Lifecycle#Initial Intrusion#Spear Phishing#Vulnerability Exploitation

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice