EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy

A penetration tester is conducting a black-box assessment against a client's web application. They discover that the application uses an outdated version of a common JavaScript library. Which of the following phases of system hacking does this finding primarily relate to?

  1. AGaining Access
  2. BMaintaining Access
  3. CVulnerability Analysis
  4. DClearing Logs
Show answer & explanation

Correct answer: C. Vulnerability Analysis

Discovering outdated software versions falls under vulnerability analysis, as it involves identifying potential weaknesses in the system that could be exploited. This phase precedes attempts to gain access or maintain presence.

Why the other options are wrong

  • A. Gaining Access is the act of exploiting a vulnerability to enter a system, which typically follows vulnerability analysis.
  • B. Maintaining Access occurs after initial compromise, focusing on persistence.
  • D. Clearing Logs is a post-exploitation activity to remove traces of an attack.

Vulnerability Analysis

The process of identifying security weaknesses and potential attack vectors in a system, application, or network.

  • Involves scanning, manual review, and research.
  • Aims to find exploitable flaws before an attacker does.
  • Often uses automated tools and vulnerability databases.

Memory trick: Remember 'R.E.C.O.N. V.A.G. M.A.C.' for the phases: Reconnaissance, Vulnerability Analysis, Gaining Access, Maintaining Access, Clearing Logs.

More System Hacking Phases and Attack Techniques questions