EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium

A client has engaged an ethical hacker to perform a penetration test on their internal network. During the 'Gaining Access' phase, the hacker discovers a critical vulnerability in a legacy application that allows arbitrary code execution. Which of the following best describes the immediate objective of exploiting this vulnerability?

  1. ATo map the entire network topology.
  2. BTo pivot to external internet-facing systems.
  3. CTo establish an initial foothold on the target system.
  4. DTo identify all user accounts on the domain controller.
Show answer & explanation

Correct answer: C. To establish an initial foothold on the target system.

In the 'Gaining Access' phase, after identifying a vulnerability, the immediate objective of exploiting it is to establish an initial presence or foothold on the target system, allowing further actions to be taken.

Why the other options are wrong

  • A. Network mapping typically occurs during reconnaissance or scanning, before gaining access.
  • B. Pivoting to external systems is unlikely and contradicts the typical flow of an internal network compromise.
  • D. Identifying user accounts is a post-exploitation information gathering activity, not the direct result of gaining access.

Gaining Access (Initial Foothold)

Gaining Access is the phase in which an attacker successfully exploits a vulnerability to enter a system or network, establishing an initial foothold.

  • Follows reconnaissance and scanning phases.
  • Involves exploiting identified vulnerabilities.
  • The primary goal is to get initial entry, often a low-privileged shell.

Memory trick: Find the door, unlock it, get a foot inside!

More System Hacking Phases and Attack Techniques questions