Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium

A SOC analyst receives an alert indicating a large number of failed login attempts from an external IP address to a critical internal server, quickly followed by a successful login from a different, unexpected external IP address for the same user account. The SIEM correlates these events. Which phase of the kill chain is most likely represented by the successful login from the second IP address?

  1. AInstallation
  2. BExploitation
  3. CWeaponization
  4. DReconnaissance
Show answer & explanation

Correct answer: B. Exploitation

The successful login from an unexpected IP after failed attempts implies that the attacker has gained valid credentials (possibly through brute force or credential stuffing) and is now using them to access the system. This act of gaining access to the system using stolen credentials falls under the Exploitation phase of the cyber kill chain.

Why the other options are wrong

  • A. Installation involves establishing a persistent presence on the compromised system.
  • C. Weaponization is combining an exploit with a backdoor into a deliverable payload.
  • D. Reconnaissance is gathering information before an attack, not active system access.

Cyber Kill Chain: Exploitation

The Exploitation phase of the cyber kill chain involves an attacker leveraging a vulnerability or stolen credentials to gain unauthorized access to a target system or network.

  • Direct action against a target.
  • Gaining initial access.
  • Often follows 'Delivery'.

Memory trick: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives.

More Security Operations questions