CS0-003 · Question #249
Several users received a phishing email containing a malicious file that bypassed the organization's email security tool. Based on the SIEM logs, users did not open the file within the environment…
The correct answer is B. Execution. Because the malicious file was delivered but never opened or run by any user, the attack halted at the point where the adversary would need to execute code on a host, so it was stopped in the Execution phase.
Question
Several users received a phishing email containing a malicious file that bypassed the organization’s email security tool. Based on the SIEM logs, users did not open the file within the environment. In which of the following phases of the MITRE ATT&CK framework was the attack stopped?
Options
- ALateral movement
- BExecution
- CInitial access
- DDiscovery
How the community answered
(36 responses)- A6% (2)
- B83% (30)
- C3% (1)
- D8% (3)
Explanation
Because the malicious file was delivered but never opened or run by any user, the attack halted at the point where the adversary would need to execute code on a host, so it was stopped in the Execution phase.
Topics
Community Discussion
No community discussion yet for this question.