
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 4
The Cyber Kill Chain Methodology TIE Practice Questions (Page 3)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
25questions here
5free pages
4concepts
Questions 11–15
- 11
Which phase of the Cyber Kill Chain is characterized by the attacker establishing a persistent communication channel with the compromised system to issue commands and receive data?
Select an answer first - 12
A threat intelligence team is using the Cyber Kill Chain to analyze a supply chain attack where the adversary compromised a software vendor's build server and injected malicious code into a legitimate software update. The team finds that the kill chain does not adequately describe the attack because the adversary did not directly target the end organization until the update was installed. Which limitation of the Cyber Kill Chain is most relevant here?
Select an answer first - 13
A security team is evaluating the Cyber Kill Chain to improve their detection capabilities. They notice that the model does not account for insider threats or attacks that originate from within the network. Which complementary model should they consider to address this gap?
Select an answer first - 14
A threat intelligence analyst is mapping an attack to the Cyber Kill Chain. The analyst notices that the attacker used a legitimate cloud storage service to host their malware and used encrypted HTTPS traffic for C2 communication. Which limitation of the Cyber Kill Chain does this scenario highlight?
Select an answer first - 15
In the Cyber Kill Chain, which phase immediately follows the 'Delivery' phase and involves the attacker's code being triggered on the target system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.