EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy

A system administrator is reviewing network traffic logs and observes unusual inbound connections on port 3389 (RDP) from external IP addresses that are not part of the organization's VPN range. Upon further investigation, it is discovered that a user's credentials were compromised, and the attacker is attempting to log in directly. Which phase of the system hacking process does this activity represent?

  1. AMaintaining Access
  2. BGaining Access
  3. CClearing Tracks
  4. DReconnaissance
Show answer & explanation

Correct answer: B. Gaining Access

Gaining Access is the phase where an attacker attempts to penetrate the system and obtain initial control. In this scenario, the attacker is actively 'attempting to log in directly' using compromised credentials, which is a direct action to gain unauthorized access to the system.

Why the other options are wrong

  • A. Maintaining access occurs *after* initial access is gained.
  • C. Clearing tracks happens at the end of the attack, after goals are achieved.
  • D. Reconnaissance is about gathering information, not active login attempts.

Gaining Access

The phase in system hacking where an attacker successfully exploits a vulnerability or uses stolen credentials to obtain initial entry into a target system or network.

  • Involves direct interaction with the target system (e.g., exploiting, logging in).
  • Can be achieved through various means like brute-force, phishing, or software exploits.
  • Marks the transition from external probing to internal presence.

Memory trick: To 'get in', you need to 'open the door' (gain access).

More System Hacking Phases and Attack Techniques questions