Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 3Objective 4

The Cyber Kill Chain Methodology TIE Practice Questions (Page 1)

Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.

25questions here
5free pages
4concepts

Questions 1–5

  1. 1foundation · easy

    Which phase of the Cyber Kill Chain involves the attacker gathering information about the target, such as email addresses, network ranges, and system vulnerabilities?

    Select an answer first
  2. 2application · medium

    An organization's security team is reviewing an attack where the attacker used a USB drop attack. The USB device contained a malicious executable that, when run, installed a keylogger. The keylogger then sent keystrokes to an external server. Which two phases of the Cyber Kill Chain are most directly demonstrated by the USB drop and the keylogger installation?

    Select an answer first
  3. 3application · medium

    A malware analyst is reverse-engineering a trojan that was delivered via a malicious email attachment. The trojan creates a scheduled task to run a PowerShell script that downloads a second-stage payload from a remote server. The analyst wants to document the phase where the trojan establishes persistence on the system. Which Cyber Kill Chain phase should the analyst assign to the creation of the scheduled task?

    Select an answer first
  4. 4application · easy

    During a threat-hunting exercise, an analyst observes that an attacker has been scanning the company's external IP range for open ports, then cross-referencing the results with employee LinkedIn profiles to identify potential targets. According to the Cyber Kill Chain, which phase is the attacker currently in?

    Select an answer first
  5. 5foundation · easy

    During an incident investigation, a security team finds that an attacker used a vulnerability in a web server to upload a web shell, then used the web shell to execute commands and eventually exfiltrated a database. According to the Cyber Kill Chain, which phase is represented by the attacker uploading the web shell?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.