ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 23 - CS0-003 discussion

Report
Export

An analyst finds that an IP address outside of the company network that is being used to run network and vulnerability scans across external-facing assets. Which of the following steps of an attack framework is the analyst witnessing?

A.
Exploitation
Answers
A.
Exploitation
B.
Reconnaissance
Answers
B.
Reconnaissance
C.
Command and control
Answers
C.
Command and control
D.
Actions on objectives
Answers
D.
Actions on objectives
Suggested answer: B

Explanation:

Reconnaissance is the first stage in the Cyber Kill Chain and involves researching potential targets before carrying out any penetration testing. The reconnaissance stage may include identifying potential targets, finding their vulnerabilities, discovering which third parties are connected to them (and what data they can access), and exploring existing entry points as well as finding new ones. Reconnaissance can take place both online and offline. In this case, an analyst finds that an IP address outside of the company network is being used to run network and vulnerability scans across external-facing assets. This indicates that the analyst is witnessing reconnaissance activity by an attacker. Official

Reference: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html

asked 02/10/2024
Dereque Datson
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first