ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 214 - CS0-003 discussion

Report
Export

An analyst discovers unusual outbound connections to an IP that was previously blocked at the web proxy and firewall. Upon further investigation, it appears that the proxy and firewall rules that were in place were removed by a service account that is not recognized. Which of the following parts of the Cyber Kill Chain does this describe?

A.
Delivery
Answers
A.
Delivery
B.
Command and control
Answers
B.
Command and control
C.
Reconnaissance
Answers
C.
Reconnaissance
D.
Weaporization
Answers
D.
Weaporization
Suggested answer: B

Explanation:

The Command and Control stage of the Cyber Kill Chain describes the communication between the attacker and the compromised system. The attacker may use this channel to send commands, receive data, or update malware. If the analyst discovers unusual outbound connections to an IP that was previously blocked, it may indicate that the attacker has established a command and control channel and bypassed the security controls.Reference:Cyber Kill Chain | Lockheed Martin

asked 02/10/2024
Andries Coetzee
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first