PCNSA · Question #17
In which stage of the Cyber-Attack Lifecycle would the attacker inject a PDF file within an email?
The correct answer is A. Weaponization. Injecting a malicious PDF file into an email is part of the Weaponization stage of the Cyber-Attack Lifecycle, where the attacker crafts the attack payload.
Question
In which stage of the Cyber-Attack Lifecycle would the attacker inject a PDF file within an email?
Options
- AWeaponization
- BReconnaissance
- CInstallation
- DCommand and Control
- EExploitation
How the community answered
(54 responses)- A94% (51)
- B4% (2)
- D2% (1)
Why each option
Injecting a malicious PDF file into an email is part of the Weaponization stage of the Cyber-Attack Lifecycle, where the attacker crafts the attack payload.
Weaponization involves packaging an exploit with a backdoor or payload into a deliverable format, such as embedding malicious code within a PDF document and preparing it for delivery via email.
Reconnaissance is the initial stage of gathering information about the target, not creating or delivering malware.
Installation occurs after successful exploitation, where the attacker installs persistent access mechanisms on the compromised system.
Command and Control (C2) is the stage where the attacker establishes communication with the compromised system to issue commands and exfiltrate data.
Exploitation is the act of leveraging a vulnerability to run code on a target system, which happens after the weaponized payload is delivered and executed.
Concept tested: Cyber-Attack Lifecycle - Weaponization stage
Source: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/threat-prevention/understand-the-cyber-attack-lifecycle
Topics
Community Discussion
No community discussion yet for this question.