Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard
A security operations center (SOC) analyst is investigating an incident where an external attacker successfully bypassed the perimeter firewall and established a persistent backdoor on an internal server. The attacker is now using this backdoor to move laterally within the network and exfiltrate sensitive data. At which stage of the Cyber Kill Chain would the attacker's actions of establishing a persistent backdoor and moving laterally be primarily categorized?
- ADelivery
- BWeaponization
- CInstallation
- DActions on Objectives
Show answer & explanationAnswer & explanation
Correct answer: C. Installation
The 'Installation' stage of the Cyber Kill Chain involves the attacker establishing persistent access to the victim's network, which includes installing backdoors or other means of maintaining presence. Lateral movement and exfiltration happen AFTER installation.
Why the other options are wrong
- A. Delivery is the transmission of the weaponized payload to the target.
- B. Weaponization involves combining an exploit with a backdoor into a deliverable payload.
- D. Actions on Objectives is the final stage where the attacker achieves their primary goals, such as data exfiltration or destruction, after installation and potentially lateral movement.
Cyber Kill Chain: Installation
The stage in the Cyber Kill Chain where the attacker establishes a persistent foothold on the target system to maintain access.
- Involves installing backdoors, creating new user accounts, or modifying existing system configurations.
- Allows the attacker to re-access the system even if initial entry methods are closed.
- Often precedes lateral movement and actions on objectives.
Memory trick: Follow the chain, from recon to objective.