EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium
A client has engaged an ethical hacker to perform a penetration test on their internal network. During the 'Gaining Access' phase, the hacker discovers a critical vulnerability in a legacy application that allows arbitrary code execution. Which of the following best describes the immediate objective of exploiting this vulnerability?
- ATo map the entire network topology.
- BTo pivot to external internet-facing systems.
- CTo establish an initial foothold on the target system.
- DTo identify all user accounts on the domain controller.
Show answer & explanationAnswer & explanation
Correct answer: C. To establish an initial foothold on the target system.
In the 'Gaining Access' phase, after identifying a vulnerability, the immediate objective of exploiting it is to establish an initial presence or foothold on the target system, allowing further actions to be taken.
Why the other options are wrong
- A. Network mapping typically occurs during reconnaissance or scanning, before gaining access.
- B. Pivoting to external systems is unlikely and contradicts the typical flow of an internal network compromise.
- D. Identifying user accounts is a post-exploitation information gathering activity, not the direct result of gaining access.
Gaining Access (Initial Foothold)
Gaining Access is the phase in which an attacker successfully exploits a vulnerability to enter a system or network, establishing an initial foothold.
- Follows reconnaissance and scanning phases.
- Involves exploiting identified vulnerabilities.
- The primary goal is to get initial entry, often a low-privileged shell.
Memory trick: Find the door, unlock it, get a foot inside!