Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A cybersecurity analyst is investigating a recent breach where an attacker gained unauthorized access to a company's internal network by exploiting a vulnerability in an outdated web server. The attacker then moved laterally to other systems, exfiltrating sensitive customer data. Which stage of the Cyber Kill Chain did the attacker successfully complete by exfiltrating the data?

  1. AWeaponization
  2. BActions on Objectives
  3. CInstallation
  4. DExploitation
Show answer & explanation

Correct answer: B. Actions on Objectives

Exfiltrating sensitive data directly achieves the attacker's goal, which falls under the 'Actions on Objectives' stage of the Cyber Kill Chain.

Why the other options are wrong

  • A. Weaponization is the bundling of an exploit with a payload, occurring before delivery.
  • C. Installation refers to establishing persistence on the target system.
  • D. Exploitation involves gaining access, not necessarily achieving the final goal.

Actions on Objectives

The final stage of the Cyber Kill Chain where an attacker achieves their primary goals, such as data exfiltration, destruction, or denial of service.

  • Represents the attacker's ultimate goal.
  • Can include data theft, corruption, or system disruption.
  • Often the most visible and damaging stage for the victim.

Memory trick: Remember 'RED' for Recon, Exploitation, and Data theft (Actions on Objectives).

More Cybersecurity Fundamentals questions