Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A security analyst is investigating a compromised system and discovers that the attacker has installed a malicious program that allows them to maintain persistent access and execute arbitrary commands remotely, even after the initial vulnerability used for entry has been patched. According to the Cyber Kill Chain, which stage has the attacker reached?

  1. ADelivery
  2. BExploitation
  3. CActions on Objectives
  4. DInstallation
Show answer & explanation

Correct answer: D. Installation

The installation of a malicious program to maintain persistent access and execute commands remotely falls under the Installation stage of the Cyber Kill Chain. This stage focuses on establishing a foothold for future use.

Why the other options are wrong

  • A. Delivery is transmitting the payload, not establishing persistence.
  • B. Exploitation is gaining initial access, which has already occurred before installation.
  • C. Actions on Objectives are the final goals, which occur after persistence is established.

Cyber Kill Chain: Installation

The stage in the Cyber Kill Chain where the attacker establishes a persistent presence on the target system, often by installing backdoors or implants.

  • Ensures continued access even if initial entry point is closed.
  • Involves creating persistence mechanisms (e.g., services, scheduled tasks).
  • Precedes Command and Control and Actions on Objectives.

Memory trick: Exploit it, Install it, then Command it!

More Cybersecurity Fundamentals questions