Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A cybersecurity team is performing a post-incident analysis after a successful data breach. They discover that the attackers gained initial access by exploiting a known vulnerability in an outdated web server, then moved laterally through the network to exfiltrate sensitive customer data. Which stage of the cyber attack kill chain was exploited for initial access?
- AWeaponization
- BDelivery
- CReconnaissance
- DExploitation
Show answer & explanationAnswer & explanation
Correct answer: D. Exploitation
The scenario explicitly states that attackers gained initial access by 'exploiting a known vulnerability'. In the cyber attack kill chain, exploitation is the stage where the attacker leverages a vulnerability to gain access to the target system.
Why the other options are wrong
- A. Weaponization is combining an exploit with a backdoor into a deliverable payload, not the act of gaining access.
- B. Delivery is the transmission of the weaponized payload to the target, not the act of gaining access.
- C. Reconnaissance involves gathering information about the target, not gaining access.
Exploitation (Cyber Kill Chain)
The stage in the cyber kill chain where an attacker leverages a vulnerability in a system or application to gain access or control.
- Occurs after delivery of a weaponized payload.
- Aims to execute code or gain unauthorized access.
- Often involves specific vulnerabilities like unpatched software or misconfigurations.
Memory trick: Remember 'Rex Wears Dark Expensive Underwear, Instantly Feeling Comfortable'