CAS-003 · Question #320
During a security assessment, activities were divided into two phases; internal and external exploitation. The security assessment team set a hard time limit on external activities before moving to…
The correct answer is A. Pivoting from the compromised, moving laterally through the enterprise, and trying to exfiltrate. After gaining an internal foothold through the external exploitation phase, the assessment team's next step is to pivot laterally through the enterprise and demonstrate data exfiltration capability.
Question
During a security assessment, activities were divided into two phases; internal and external exploitation. The security assessment team set a hard time limit on external activities before moving to a compromised box within the enterprise perimeter. Which of the following methods is the assessment team most likely to employ NEXT?
Options
- APivoting from the compromised, moving laterally through the enterprise, and trying to exfiltrate
- BConducting a social engineering attack attempt with the goal of accessing the compromised box
- CExfiltrating network scans from the compromised box as a precursor to social media
- DOpen-source intelligence gathering to identify the network perimeter and scope to enable further
How the community answered
(56 responses)- A71% (40)
- B11% (6)
- C4% (2)
- D14% (8)
Why each option
After gaining an internal foothold through the external exploitation phase, the assessment team's next step is to pivot laterally through the enterprise and demonstrate data exfiltration capability.
With an internal compromised host established, standard red team methodology calls for pivoting from that machine to move laterally through the enterprise network - escalating privileges, accessing sensitive systems, and ultimately attempting data exfiltration - to simulate the full kill chain of an advanced persistent threat.
Social engineering is an initial access technique used to gain the first foothold; with a box already compromised inside the perimeter, this phase has already been completed and social engineering would be redundant.
Exfiltrating network scans as a precursor to social media is not a recognized penetration testing phase and conflates post-exploitation reconnaissance output with an irrelevant external channel.
OSINT and external network perimeter reconnaissance are pre-engagement and initial external phase activities performed before any internal access is achieved, not activities conducted after a host is compromised internally.
Concept tested: Post-compromise lateral movement and exfiltration in penetration testing
Source: https://attack.mitre.org/tactics/TA0008/
Topics
Community Discussion
No community discussion yet for this question.