nerdexam
CompTIA

CAS-003 · Question #320

During a security assessment, activities were divided into two phases; internal and external exploitation. The security assessment team set a hard time limit on external activities before moving to…

The correct answer is A. Pivoting from the compromised, moving laterally through the enterprise, and trying to exfiltrate. After gaining an internal foothold through the external exploitation phase, the assessment team's next step is to pivot laterally through the enterprise and demonstrate data exfiltration capability.

Enterprise Security Operations

Question

During a security assessment, activities were divided into two phases; internal and external exploitation. The security assessment team set a hard time limit on external activities before moving to a compromised box within the enterprise perimeter. Which of the following methods is the assessment team most likely to employ NEXT?

Options

  • APivoting from the compromised, moving laterally through the enterprise, and trying to exfiltrate
  • BConducting a social engineering attack attempt with the goal of accessing the compromised box
  • CExfiltrating network scans from the compromised box as a precursor to social media
  • DOpen-source intelligence gathering to identify the network perimeter and scope to enable further

How the community answered

(56 responses)
  • A
    71% (40)
  • B
    11% (6)
  • C
    4% (2)
  • D
    14% (8)

Why each option

After gaining an internal foothold through the external exploitation phase, the assessment team's next step is to pivot laterally through the enterprise and demonstrate data exfiltration capability.

APivoting from the compromised, moving laterally through the enterprise, and trying to exfiltrateCorrect

With an internal compromised host established, standard red team methodology calls for pivoting from that machine to move laterally through the enterprise network - escalating privileges, accessing sensitive systems, and ultimately attempting data exfiltration - to simulate the full kill chain of an advanced persistent threat.

BConducting a social engineering attack attempt with the goal of accessing the compromised box

Social engineering is an initial access technique used to gain the first foothold; with a box already compromised inside the perimeter, this phase has already been completed and social engineering would be redundant.

CExfiltrating network scans from the compromised box as a precursor to social media

Exfiltrating network scans as a precursor to social media is not a recognized penetration testing phase and conflates post-exploitation reconnaissance output with an irrelevant external channel.

DOpen-source intelligence gathering to identify the network perimeter and scope to enable further

OSINT and external network perimeter reconnaissance are pre-engagement and initial external phase activities performed before any internal access is achieved, not activities conducted after a host is compromised internally.

Concept tested: Post-compromise lateral movement and exfiltration in penetration testing

Source: https://attack.mitre.org/tactics/TA0008/

Topics

#penetration testing#lateral movement#pivoting#post-exploitation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice