200-201 Question 397
Select 4A security analyst is investigating an intrusion event where an attacker gained access to a system through a phishing email. The attacker then installed a backdoor to maintain persistence and began exfiltrating sensitive data. According to the Cyber Kill Chain model, which of the following stages are associated with this intrusion event?
- A
Delivery
- B
Exploitation
- C
Command and Control
- D
Exfiltration
- E
Weaponization
- F
Reconnaissance
Show answer and explanation
Correct answers: A, B, C, D
Explanation
The Cyber Kill Chain model provides a structured approach to understanding and categorizing intrusion events. In this scenario, the stages of Delivery, Exploitation, Command and Control, and Exfiltration are present. Delivery refers to the phishing email, Exploitation involves executing the malicious payload, Command and Control refers to maintaining persistence via the backdoor, and Exfiltration involves the theft of sensitive data. Weaponization and Reconnaissance are not directly applicable to the described intrusion activity.
- A. Correct.
Delivery is correct because the phishing email was the mechanism used to deliver the malicious payload to the victim.
- B. Correct.
Exploitation is correct because the attacker exploited the system by executing the malicious payload through the phishing email.
- C. Correct.
Command and Control is correct because the backdoor allowed the attacker to maintain communication with the compromised system.
- D. Correct.
Exfiltration is correct because the attacker actively stole sensitive data from the compromised system.
- E. Incorrect.
Weaponization is incorrect because this stage involves preparing the malicious payload before delivery, which is not part of the analyst's investigation.
- F. Incorrect.
Reconnaissance is incorrect because this stage involves gathering information about the target before the attack, which is not described in this scenario.