CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is reviewing logs from a web application firewall (WAF) and observes a high volume of requests targeting known vulnerable endpoints and attempting to inject SQL commands into input fields. These requests originate from various IP addresses globally and are repetitive in nature, attempting common attack patterns. Which phase of the Cyber Kill Chain does this activity most accurately represent?
- AWeaponization
- BActions on Objectives
- CExploitation
- DInstallation
Show answer & explanationAnswer & explanation
Correct answer: C. Exploitation
The activity described, involving attempts to inject SQL commands into input fields and targeting vulnerable endpoints, directly corresponds to the 'Exploitation' phase of the Cyber Kill Chain. In this phase, the attacker leverages a vulnerability to gain access or execute code on the target system.
Why the other options are wrong
- A. Weaponization is the phase where the attacker combines an exploit with a backdoor into a deliverable payload.
- B. Actions on Objectives is the final phase where the attacker achieves their ultimate goals, such as data exfiltration or system destruction.
- D. Installation is when the attacker establishes persistence on the compromised system.
Cyber Kill Chain: Exploitation
The phase where the attacker leverages a vulnerability to execute code on a target system or gain unauthorized access.
- Occurs after Weaponization and Delivery.
- Involves triggering a vulnerability (e.g., SQL injection, buffer overflow).
- Aims to gain initial access or control.
Memory trick: Recon, Weapon, Deliver, Exploit, Install, Command, Objectives – Remember the sequence to catch the bad guys!