EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy

A penetration tester is conducting a black-box assessment against a client's web application. They discover that the application is vulnerable to SQL injection. Which phase of system hacking does this discovery primarily fall under?

  1. AVulnerability Analysis
  2. BGaining Access
  3. CClearing Logs
  4. DMaintaining Access
Show answer & explanation

Correct answer: A. Vulnerability Analysis

Discovering vulnerabilities like SQL injection, before exploiting them for access, is a core activity within the vulnerability analysis phase. This phase focuses on identifying weaknesses.

Why the other options are wrong

  • B. Gaining Access occurs after vulnerabilities are identified and exploited to enter the system.
  • C. Clearing Logs is a post-exploitation activity to remove traces of an attack.
  • D. Maintaining Access refers to the actions taken to ensure continued access to a compromised system.

Vulnerability Analysis

Vulnerability analysis is the process of identifying and evaluating security weaknesses in a system, application, or network.

  • Precedes exploitation efforts.
  • Aims to discover potential entry points.
  • Can use automated tools or manual techniques.

Memory trick: Recon, Scan, Gain, Maintain, Clear, Cover your tracks!

More System Hacking Phases and Attack Techniques questions