EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
A penetration tester is conducting a black-box assessment against a client's web application. They discover that the application is vulnerable to SQL injection. Which phase of system hacking does this discovery primarily fall under?
- AVulnerability Analysis
- BGaining Access
- CClearing Logs
- DMaintaining Access
Show answer & explanationAnswer & explanation
Correct answer: A. Vulnerability Analysis
Discovering vulnerabilities like SQL injection, before exploiting them for access, is a core activity within the vulnerability analysis phase. This phase focuses on identifying weaknesses.
Why the other options are wrong
- B. Gaining Access occurs after vulnerabilities are identified and exploited to enter the system.
- C. Clearing Logs is a post-exploitation activity to remove traces of an attack.
- D. Maintaining Access refers to the actions taken to ensure continued access to a compromised system.
Vulnerability Analysis
Vulnerability analysis is the process of identifying and evaluating security weaknesses in a system, application, or network.
- Precedes exploitation efforts.
- Aims to discover potential entry points.
- Can use automated tools or manual techniques.
Memory trick: Recon, Scan, Gain, Maintain, Clear, Cover your tracks!