nerdexam
Palo_Alto_Networks

PCDRA · Question #49

Which of the following represents a common sequence of cyber attack tactics?

The correct answer is D. Reconnaissance >> Weaponisation & Delivery >> Exploitation >> Installation >> Command &. The correct sequence of cyber attack tactics typically follows the stages of the cyber kill chain, starting with reconnaissance and progressing through exploitation to achieve the attacker's objective.

Submitted by marco_it· Apr 18, 2026Investigation and Response

Question

Which of the following represents a common sequence of cyber attack tactics?

Options

  • AActions on the objective >> Reconnaissance >> Weaponisation & Delivery >> Exploitation >>
  • BInstallation >> Reconnaissance >> Weaponisation & Delivery >> Exploitation >> Command &
  • CReconnaissance >> Installation >> Weaponisation & Delivery >> Exploitation >> Command &
  • DReconnaissance >> Weaponisation & Delivery >> Exploitation >> Installation >> Command &

How the community answered

(29 responses)
  • A
    3% (1)
  • C
    7% (2)
  • D
    90% (26)

Why each option

The correct sequence of cyber attack tactics typically follows the stages of the cyber kill chain, starting with reconnaissance and progressing through exploitation to achieve the attacker's objective.

AActions on the objective >> Reconnaissance >> Weaponisation & Delivery >> Exploitation >>

Reconnaissance occurs early in the attack, not after 'Actions on the objective'.

BInstallation >> Reconnaissance >> Weaponisation & Delivery >> Exploitation >> Command &

Reconnaissance is an initial stage, not occurring after 'Installation'.

CReconnaissance >> Installation >> Weaponisation & Delivery >> Exploitation >> Command &

Installation typically occurs after exploitation and before establishing C2, not before weaponization.

DReconnaissance >> Weaponisation & Delivery >> Exploitation >> Installation >> Command &Correct

This sequence aligns with the Lockheed Martin Cyber Kill Chain model, which describes the stages an adversary typically follows: Reconnaissance (information gathering), Weaponization (pairing exploit with payload), Delivery (transmitting weapon), Exploitation (triggering vulnerability), Installation (persistence), Command & Control (remote access), and Actions on Objective (achieving goals).

Concept tested: Cyber Kill Chain stages

Source: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html

Topics

#Cyber Kill Chain#Attack lifecycle#Adversary tactics#Incident investigation

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice