nerdexam
CompTIA

CS0-003 · Question #249

Several users received a phishing email containing a malicious file that bypassed the organization's email security tool. Based on the SIEM logs, users did not open the file within the environment…

The correct answer is B. Execution. Because the malicious file was delivered but never opened or run by any user, the attack halted at the point where the adversary would need to execute code on a host, so it was stopped in the Execution phase.

Submitted by javi_es· Mar 6, 2026Security operations

Question

Several users received a phishing email containing a malicious file that bypassed the organization’s email security tool. Based on the SIEM logs, users did not open the file within the environment. In which of the following phases of the MITRE ATT&CK framework was the attack stopped?

Options

  • ALateral movement
  • BExecution
  • CInitial access
  • DDiscovery

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    83% (30)
  • C
    3% (1)
  • D
    8% (3)

Explanation

Because the malicious file was delivered but never opened or run by any user, the attack halted at the point where the adversary would need to execute code on a host, so it was stopped in the Execution phase.

Topics

#MITRE ATT&CK#Phishing#Email security#Attack phases

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice