312-50V13 · Question #244
Harry. a professional hacker, targets the IT infrastructure of an organization. After preparing for the attack, he attempts to enter the target network using techniques such as sending spear…
The correct answer is D. Initial Intrusion. APT Lifecycle Phase Explanation Option D (Initial Intrusion) is correct because Harry is actively breaching the target network for the first time using attack vectors like spear-phishing emails and exploiting public-facing server vulnerabilities - this is the defining…
Question
Options
- APreparation
- BCleanup
- CPersistence
- DInitial Intrusion
How the community answered
(55 responses)- A11% (6)
- B5% (3)
- C4% (2)
- D80% (44)
Explanation
APT Lifecycle Phase Explanation
Option D (Initial Intrusion) is correct because Harry is actively breaching the target network for the first time using attack vectors like spear-phishing emails and exploiting public-facing server vulnerabilities - this is the defining characteristic of the Initial Intrusion phase, where the attacker gains their first foothold by deploying malware to establish an outbound (C2) connection.
Why the distractors are wrong:
- A (Preparation) occurs before the attack begins - it involves reconnaissance, building tools, and selecting targets, which Harry has already completed
- C (Persistence) comes after initial intrusion, when the attacker works to maintain long-term access to the compromised system
- B (Cleanup) is the final phase, where attackers remove traces of their activity to avoid detection after achieving their objectives
Memory Tip: Think of the APT lifecycle as a burglary analogy - Preparation = casing the building, Initial Intrusion = breaking through the front door, Persistence = hiding inside, and Cleanup = wiping fingerprints. Whenever you see first entry methods like phishing or exploiting public servers, that's your signal for Initial Intrusion.
Topics
Community Discussion
No community discussion yet for this question.