Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A security operations center (SOC) analyst is investigating an incident where an external attacker successfully gained initial access to a company's network by exploiting a known vulnerability in an outdated web server. The attacker then used this access to map the internal network and identify other vulnerable systems. According to the Cyber Kill Chain model, which stage does the act of identifying other vulnerable systems fall under?

  1. AReconnaissance
  2. BWeaponization
  3. CDelivery
  4. DExploitation
Show answer & explanation

Correct answer: A. Reconnaissance

After gaining initial access (Exploitation), the attacker's action of mapping the internal network and identifying other vulnerable systems is a form of internal reconnaissance, which aims to gather more information for further attacks.

Why the other options are wrong

  • B. Weaponization involves pairing an exploit with a backdoor into a deliverable payload.
  • C. Delivery is the transmission of the weaponized payload to the target.
  • D. Exploitation is the execution of the exploit to gain access, which already occurred to gain initial access.

Cyber Kill Chain: Reconnaissance

The first phase of the Cyber Kill Chain, where an attacker gathers information about a target before initiating an attack.

  • Can be passive (OSINT) or active (scanning)
  • Aims to identify vulnerabilities and potential entry points
  • Occurs both pre-attack and post-compromise (internal reconnaissance)

Memory trick: RWCDEIC: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives – The attacker's journey.

More Cybersecurity Fundamentals questions