Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard

A security analyst is investigating a compromised system and discovers that the attacker exploited a vulnerability in a web application to gain elevated privileges on the server. The attacker then used these privileges to install a rootkit, which hides their presence and maintains persistent access. This sequence of actions best exemplifies which stage of the cyber kill chain?

  1. AReconnaissance
  2. BActions on Objectives
  3. CWeaponization
  4. DInstallation
Show answer & explanation

Correct answer: D. Installation

The 'Installation' phase of the cyber kill chain involves the attacker establishing persistent access to the target system, often through backdoors or rootkits, after gaining initial access.

Why the other options are wrong

  • A. Reconnaissance is the first phase, where attackers gather information about the target.
  • B. Actions on Objectives is the final phase, where the attacker achieves their primary goal (e.g., data exfiltration, destruction).
  • C. Weaponization involves coupling an exploit with a backdoor into a deliverable payload.

Cyber Kill Chain: Installation

The Installation phase of the Lockheed Martin Cyber Kill Chain describes the attacker's actions to establish a persistent foothold on the compromised system, often through the use of backdoors, rootkits, or other mechanisms.

  • Occurs after initial exploitation and delivery.
  • Focuses on maintaining access for future operations.
  • Examples include installing web shells, rootkits, or creating new user accounts.

Memory trick: R-W-D-E-I-C-A: Really Wicked Dogs Eat Icy Cold Apples.

More Cybersecurity Fundamentals questions