Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsHard

During a forensic investigation, a security analyst discovers that an attacker gained initial access to an internal network by exploiting a vulnerability in a publicly accessible web application. The attacker then used this foothold to scan internal systems, identify a misconfigured database, and exfiltrate sensitive customer data. This sequence of events best illustrates which phase of the cyber attack kill chain?

  1. AExploitation
  2. BDelivery
  3. CActions on Objectives
  4. DWeaponization
Show answer & explanation

Correct answer: C. Actions on Objectives

The cyber attack kill chain outlines the stages of a typical cyber attack. 'Actions on Objectives' is the final stage where the attacker achieves their ultimate goal, which in this scenario is 'exfiltrate sensitive customer data' after gaining access and reconnaissance. While exploitation occurred, the full scenario describes the successful completion of the attacker's ultimate goal.

Why the other options are wrong

  • A. Exploitation is the stage where the vulnerability is triggered to execute code on the target system, granting initial access.
  • B. Delivery is the transmission of the weaponized payload to the target (e.g., via email, web).
  • D. Weaponization is the stage where the attacker combines an exploit with a backdoor into a deliverable payload.

Cyber Attack Kill Chain

A model developed by Lockheed Martin that outlines the stages of a typical cyber attack, from reconnaissance to achieving the attacker's objective.

  • Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives.
  • Helps security teams understand and disrupt attack progression.
  • Focuses on preventing the attacker from achieving their goal.

Memory trick: Kill Chain is a sequence: Recon, Weaponize, Deliver, Exploit, Install, C2, Objectives.

More Cybersecurity Fundamentals questions