CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A web server access log shows the following sequence of requests from a single external IP address over two minutes, with no exploitation attempts or payloads submitted: `10:02:11 GET /robots.txt 200 10:02:12 GET /sitemap.xml 200 10:02:15 GET /.git/config 404 10:02:20 GET /admin/login.php 200` According to the Cyber Kill Chain, which phase does this activity represent?

  1. AReconnaissance
  2. BDelivery
  3. CWeaponization
  4. DExploitation
Show answer & explanation

Correct answer: A. Reconnaissance

The requests are purely information-gathering — enumerating site structure, checking for exposed configuration files, and locating admin login pages — with no malicious payload delivered. This maps to the Reconnaissance phase, where the attacker studies the target before crafting or delivering a weapon.

Why the other options are wrong

  • B. Delivery involves transmitting a weaponized payload to the target, which is absent here.
  • C. Weaponization happens offline when the attacker builds a malicious payload, not during web requests.
  • D. Exploitation requires triggering a vulnerability, which has not occurred yet.

Cyber Kill Chain: Reconnaissance

The first phase of the Lockheed Martin Cyber Kill Chain, where an attacker gathers information about the target such as open ports, exposed files, and personnel details.

  • Includes OSINT, scanning, and enumeration
  • No payload or exploit is delivered yet
  • Precedes Weaponization and Delivery phases

Memory trick: Recon-Weapon-Deliver-Exploit-Install-C2-Act: 'Really Wicked Delivery Exploits Install Control Actions'

More Vulnerability Management questions