CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

During malware analysis, an incident responder determines that the attacker took a known Adobe Reader exploit and bundled it with a custom remote access trojan into a single malicious PDF file before ever sending it to the target. Which phase of the Cyber Kill Chain does this activity represent?

  1. AReconnaissance
  2. BInstallation
  3. CDelivery
  4. DWeaponization
Show answer & explanation

Correct answer: D. Weaponization

Weaponization is the Kill Chain phase in which an attacker couples an exploit with a payload (such as a trojan) into a deliverable artifact, occurring before the artifact is ever sent to a victim.

Why the other options are wrong

  • A. Reconnaissance involves gathering information about the target, not building the malicious artifact.
  • B. Installation refers to the malware establishing persistence after execution on the victim system.
  • C. Delivery is the transmission of the weaponized artifact to the victim, which has not yet occurred.

Cyber Kill Chain: Weaponization

The stage where an attacker combines an exploit with a malicious payload to create a deliverable weapon (e.g., malicious document, executable).

  • Occurs before Delivery
  • Often produces a booby-trapped file (PDF, macro, executable)
  • Second phase of Lockheed Martin's Cyber Kill Chain

Memory trick: Recon-Weaponize-Deliver-Exploit-Install-C2-Actions.

More Vulnerability Management questions