CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
An email security gateway captured the following log entry: `2024-03-11 08:42:10 SMTP-IN from=finance-alert@extern4l-billing.com to=ap@corp.com subject="Invoice_0398_Overdue.docm" attachment=Invoice_0398_Overdue.docm size=142KB action=DELIVERED` Minutes later, the recipient opened the attachment and enabled macros, triggering a download of a second-stage payload. According to the Lockheed Martin Cyber Kill Chain, which phase does the email log entry itself represent?
- AExploitation
- BWeaponization
- CDelivery
- DActions on Objectives
Show answer & explanationAnswer & explanation
Correct answer: C. Delivery
Delivery is the phase in which the attacker transmits the weaponized payload to the target, such as sending a malicious attachment via email; this log entry captures that transmission and successful delivery. Weaponization already occurred earlier when the malicious .docm was crafted, and Exploitation happens next when the macro executes.
Why the other options are wrong
- A. Exploitation occurs when the macro runs and code executes, which happens after this log entry.
- B. Weaponization is the crafting of the malicious document before it is ever sent.
- D. Actions on Objectives refers to the attacker achieving their final goal, far later in the chain.
Cyber Kill Chain: Delivery
The third phase of the Lockheed Martin Cyber Kill Chain, in which the attacker transmits the weaponized payload to the target via a vector such as email, USB, or a compromised website.
- Follows Weaponization (payload creation) and precedes Exploitation (payload execution)
- Common delivery vectors: phishing email, watering-hole sites, removable media
- Blocking delivery (e.g., email filtering) breaks the chain before exploitation can occur
Memory trick: Recon-Weapon-Deliver-Exploit-Install-C2-Act: the mailman drops the bomb at Delivery.