312-50 exam dumps

312-50 practice question 160 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 160

Single answer▪ APT Concepts

A financial services company discovers that an attacker has maintained access to a small set of executive workstations for several months without triggering signature-based alerts. The incident response team finds evidence of spear-phishing, use of legitimate administrative tools for lateral movement, encrypted outbound connections to rare external hosts, and periodic data staging before exfiltration. Which assessment BEST describes this activity in terms of APT concepts?

  1. A

    This is most consistent with an Advanced Persistent Threat because the attacker used targeted initial access, long-term stealthy persistence, and staged exfiltration while adapting techniques to avoid detection.

  2. B

    This is a typical opportunistic malware outbreak because any compromise involving phishing and outbound traffic is considered commodity malware rather than an APT.

  3. C

    This is primarily a denial-of-service campaign because the attacker established multiple outbound connections from internal systems to external hosts.

  4. D

    This is a one-time insider data theft event because the data was staged before leaving the environment.

Show answer and explanation

Correct answer: A

Explanation

An Advanced Persistent Threat is generally characterized by targeted intrusion, sustained unauthorized access, stealth, and achievement of a strategic objective such as espionage or data theft. In this scenario, several hallmarks are present: spear-phishing as a targeted initial access vector, long dwell time, living-off-the-land behavior using legitimate administrative tools, encrypted command-and-control traffic, and staged exfiltration. These behaviors are consistent with guidance from sources such as NIST SP 800-61 on incident handling and MITRE ATT&CK techniques covering phishing, persistence, lateral movement, command and control, collection, and exfiltration. For CEH candidates, the key skill is recognizing that APT classification depends on the campaign's persistence, sophistication, and objectives, not merely the presence of malware or phishing alone.

  • A. Correct.

    Correct. The scenario aligns closely with core APT characteristics: targeted delivery via spear-phishing, persistence over an extended period, stealthy operations, use of living-off-the-land techniques such as legitimate administrative tools, command-and-control communications, and organized collection/staging/exfiltration. In CEH context, an APT is distinguished not just by malware usage but by a coordinated, adaptive campaign intended to maintain access and achieve a strategic objective while minimizing detection.

  • B. Incorrect.

    Incorrect. Phishing can be used by both commodity malware and APT actors, but the key indicators here are the duration of access, selective targeting of executives, stealth, use of legitimate tools, and periodic staged exfiltration. Those factors point to a deliberate campaign rather than a broad, opportunistic outbreak. A common misconception is to classify any phishing-led compromise as commodity malware without considering the persistence and operational discipline shown after initial access.

  • C. Incorrect.

    Incorrect. Denial-of-service attacks are intended to disrupt availability by overwhelming or exhausting resources. In this scenario, the outbound connections are part of covert command-and-control or exfiltration behavior, not service disruption. The presence of persistence, lateral movement, and data staging further contradicts a DoS classification.

  • D. Incorrect.

    Incorrect. Insider threats may also involve data staging, but the scenario includes external spear-phishing, encrypted outbound communication to rare external hosts, and use of administrative tools for lateral movement after compromise. Those are stronger indicators of an external threat actor conducting an APT-style intrusion rather than a purely insider-driven theft. The misconception here is treating data staging as uniquely indicative of insiders.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam