ExamGecko
Question list
Search
Search

Related questions











Question 321 - 200-201 discussion

Report
Export

A security engineer must investigate a recent breach within the organization. An engineer noticed that a breached workstation is trying to connect to the domain 'Ranso4730-mware92-647'. which is known as malicious. In which step of the Cyber Kill Chain is this event?

A.

Vaporization

Answers
A.

Vaporization

B.

Delivery

Answers
B.

Delivery

C.

reconnaissance

Answers
C.

reconnaissance

D.

Action on objectives

Answers
D.

Action on objectives

Suggested answer: D

Explanation:

The event where a breached workstation is trying to connect to a known malicious domain suggests that the attacker is moving towards their end goals, which typically involves actions on objectives.

In the Cyber Kill Chain framework, 'Action on objectives' refers to the steps taken by an attacker to achieve their intended outcomes, such as data exfiltration, destruction, or ransom demands.

This phase involves the attacker executing their final mission within the target environment, leveraging access gained in earlier stages of the attack.

Lockheed Martin Cyber Kill Chain

Understanding the Stages of Cyber Attacks

Incident Response and the Cyber Kill Chain

asked 07/10/2024
Martin Gucký
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first