nerdexam
Huawei

H12-725_V4.0 · Question #68

The "Stuxnet" virus is a worm that attacks industrial control systems. Which of the following is the correct ranking of the Stuxnet virus attack process?

The correct answer is C. Reconnaissance of organizational structure and personnel information->Social engineering. Option C correctly reflects Stuxnet's logical attack sequence: reconnaissance first, then social engineering, then target identification, then attack. Attackers must gather intelligence about the organization and its personnel before they can craft believable social engineering…

Network Security Solution Design

Question

The "Stuxnet" virus is a worm that attacks industrial control systems. Which of the following is the correct ranking of the Stuxnet virus attack process?

Options

  • AReconnaissance of organizational structure and personnel information->Social engineering
  • BFind infection targets -> Reconnaissance of organizational structure and personnel information ->
  • CReconnaissance of organizational structure and personnel information->Social engineering
  • DSocial engineering penetration -> Reconnaissance of organizational structure and personnel

How the community answered

(53 responses)
  • A
    9% (5)
  • B
    4% (2)
  • C
    85% (45)
  • D
    2% (1)

Explanation

Option C correctly reflects Stuxnet's logical attack sequence: reconnaissance first, then social engineering, then target identification, then attack. Attackers must gather intelligence about the organization and its personnel before they can craft believable social engineering lures (such as the infected USB drives used against Iranian nuclear facilities) - you can't manipulate people you haven't profiled.

Why the distractors fail:

  • Option A appears similar to C but diverges in the later steps of the sequence, placing actions out of their logical dependency order.
  • Option B starts with "Find infection targets," which is backwards - you can't locate specific ICS/SCADA systems to infect until you've done reconnaissance and gained initial access through social engineering.
  • Option D reverses the first two steps, putting social engineering before reconnaissance. This is logically impossible: you need organizational intel to identify who to socially engineer and how.

Memory tip: Think of it as a funnel - Recon → Social Engineering → Target → Attack. Stuxnet worked from the outside in: learn the organization, trick a human insider, find the industrial systems, then strike. The human layer always comes after intelligence gathering but before the technical payload delivery.

Topics

#Stuxnet Attack#Reconnaissance#Social Engineering#Attack Methodology

Community Discussion

No community discussion yet for this question.

Full H12-725_V4.0 Practice