312-85 · Question #45
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login…
The correct answer is C. Expansion. Option C (Expansion) is correct because John has already breached the network (initial intrusion is done) and is now attempting to obtain administrative credentials to move laterally and compromise additional systems - which is the defining characteristic of the Expansion…
Question
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques. What phase of the advanced persistent threat lifecycle is John currently in?
Options
- AInitial intrusion
- BSearch and exfiltration
- CExpansion
- DPersistence
How the community answered
(37 responses)- A16% (6)
- B3% (1)
- C70% (26)
- D11% (4)
Explanation
Option C (Expansion) is correct because John has already breached the network (initial intrusion is done) and is now attempting to obtain administrative credentials to move laterally and compromise additional systems - which is the defining characteristic of the Expansion phase.
- A (Initial intrusion) is wrong because that phase covers the very first breach of the perimeter (e.g., spear phishing, exploiting a public-facing vulnerability). John has already completed this step by gaining access to his first system.
- B (Search and exfiltration) is wrong because that phase involves locating sensitive data and sending it outside the organization - John isn't stealing data yet, he's still trying to widen his foothold.
- D (Persistence) is wrong because persistence focuses on maintaining long-term, covert access (e.g., planting backdoors, creating rogue accounts) so the attacker can return - not on spreading to new systems.
Memory tip: Think of APT phases in order - get in → dig in → spread out → steal. "Expansion" = spreading out by harvesting credentials and pivoting to new machines, which maps directly to what John is doing here.
Topics
Community Discussion
No community discussion yet for this question.