ETExamTower
Q19Fundamentals

DRAG DROP - Drag and drop the type of attacks from the left onto the cyber kill chain stages at which the attacks are seen on the right. Select and Place: <DragDrop items={["not visible to the victim","virus scanner turning off","malware placed on the targeted system","open port scans and multiple failed logins from the website","large amount of data leaving the network through unusual ports","system phones connecting to countries where no staff are located","USB with infected files inserted into company laptop"]} slots={[{"answer":"open port scans and multiple failed logins from the website","id":"reconnaissance","label":"reconnaissance"},{"answer":"not visible to the victim","id":"weaponization","label":"weaponization"},{"answer":"USB with infected files inserted into company laptop","id":"delivery","label":"delivery"},{"answer":"virus scanner turning off","id":"exploitation","label":"exploitation"},{"answer":"malware placed on the targeted system","id":"installation","label":"installation"},{"answer":"system phones connecting to countries where no staff are located","id":"command_control","label":"command & control"},{"answer":"large amount of data leaving the network through unusual ports","id":"actions_objectives","label":"actions on objectives"}]} explanation={"Reconnaissance often appears as port scans and login attempts. Weaponization prepares evasive malware, delivery introduces it through a vector such as infected removable media, exploitation executes malicious activity such as disabling security controls, and installation places malware on the victim system. Command and control produces suspicious outbound communications, while actions on objectives can include exfiltrating substantial data.\n\n**Learn more:** [Lockheed Martin Cyber Kill Chain](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html)"} reuse={false} />

Question exhibit
← → navigate · a answer
Discussion · 7
5
Reconnaissance - Open port scans and several failed logins from the websites Weaponization - Not visible to the victim Delivery - USB with infected files plugged into company laptop Exploitation - Virus scanner turning off Installation - Malware placed on the targeted system C&C - System phones connecting to countries where no staff are located Actions on objectives - Large amount of data leaving the network through unusual ports
2
I think the answer is incorrect according to this: https://www.logsign.com/blog/7-steps-of-cyber-kill-chain/ For me: Reconnaissance - Not visible to the victim Weaponization - Virus scanner turning off Delivery - USB with infected files plugged into company laptop Exploitation - Open port scans and multiple failed logins from the websites Installation - Malware placed on the targeted system C&C - System phones connecting to countries where no staff are located Actions on objectives - Large amount of data leaving the network through unusual ports
2
Note: Weaponization is preparation by the hacker. Not visible to anyone else
2
I think it's below. Virus scanner turning off can't be weaponization because it is the threat actor preparation process without any action. Reconnaissance - Open port scans and several failed logins from the websites Weaponization - Not visible to the victim Delivery - USB with infected files plugged into company laptop Exploitation - Virus scanner turning off Installation - Malware placed on the targeted system C&C - System phones connecting to countries where no staff are located Actions on objectives - Large amount of data leaving the network through unusual ports
1
Reconnaissance - Not visible to the victim Weaponization - Virus scanner turning off Delivery - USB with infected files plugged into company laptop Exploitation - Open port scans and multiple failed logins from the websites Installation - Malware placed on the targeted system C&C - System phones connecting to countries where no staff are located Actions on objectives - Large amount of data leaving the network through unusual ports
1
Reconnaissance - Open port scans and several failed logins from the websites Weaponization - Not visible to the victim Delivery - USB with infected files plugged into company laptop Exploitation - Virus scanner turning off Installation - Malware placed on the targeted system C&C - System phones connecting to countries where no staff are located Actions on objectives - Large amount of data leaving the network through unusual ports
1
Explanation: Reconnaissance: Open port scans and multiple failed logins from website Weaponization: Virus scanner Turing off Delivery: Malware placed on the targeted system Exploitation: Large amount of data leaving the network through unusual ports Installation: Usb with infected files inserted into company laptop Command and Control: System phone connecting to the countries where not staff are located Actions on Objectives: Not visible to the victim - ChatGPT