nerdexam
EC-Council

312-85 · Question #45

John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login…

The correct answer is C. Expansion. Option C (Expansion) is correct because John has already breached the network (initial intrusion is done) and is now attempting to obtain administrative credentials to move laterally and compromise additional systems - which is the defining characteristic of the Expansion…

Threat Intelligence Analysis

Question

John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques. What phase of the advanced persistent threat lifecycle is John currently in?

Options

  • AInitial intrusion
  • BSearch and exfiltration
  • CExpansion
  • DPersistence

How the community answered

(37 responses)
  • A
    16% (6)
  • B
    3% (1)
  • C
    70% (26)
  • D
    11% (4)

Explanation

Option C (Expansion) is correct because John has already breached the network (initial intrusion is done) and is now attempting to obtain administrative credentials to move laterally and compromise additional systems - which is the defining characteristic of the Expansion phase.

  • A (Initial intrusion) is wrong because that phase covers the very first breach of the perimeter (e.g., spear phishing, exploiting a public-facing vulnerability). John has already completed this step by gaining access to his first system.
  • B (Search and exfiltration) is wrong because that phase involves locating sensitive data and sending it outside the organization - John isn't stealing data yet, he's still trying to widen his foothold.
  • D (Persistence) is wrong because persistence focuses on maintaining long-term, covert access (e.g., planting backdoors, creating rogue accounts) so the attacker can return - not on spreading to new systems.

Memory tip: Think of APT phases in order - get in → dig in → spread out → steal. "Expansion" = spreading out by harvesting credentials and pivoting to new machines, which maps directly to what John is doing here.

Topics

#APT lifecycle phases#Lateral movement#Privilege escalation#Expansion

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice