
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 4
The Cyber Kill Chain Methodology TIE Practice Questions (Page 4)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
25questions here
5free pages
4concepts
Questions 16–20
- 16
A security operations center (SOC) is reviewing a multi-stage attack. The attacker first scanned the network and identified a vulnerable web application. They then exploited a SQL injection vulnerability to upload a web shell. The web shell was used to establish a reverse shell to a command-and-control server. The attacker then used the reverse shell to move laterally and eventually exfiltrated a database. The SOC wants to map this attack to the Cyber Kill Chain to identify detection opportunities. Which mapping is most accurate?
Select an answer first - 17
An analyst observes that an attacker sent a phishing email with a malicious attachment to an employee. The employee opened the attachment, which exploited a vulnerability in the PDF reader and installed a backdoor. The attacker then connected to the backdoor to access the corporate network. At which phase of the Cyber Kill Chain did the attacker connect to the backdoor?
Select an answer first - 18
A security analyst is documenting an attack where the attacker used a publicly available exploit kit to deliver a payload that exploited a browser vulnerability. The payload then downloaded a banking trojan. The analyst needs to identify the phase where the attacker uses the exploit kit to deliver the payload. Which phase is this?
Select an answer first - 19
A threat intelligence analyst is documenting an attack where the adversary harvested email addresses from LinkedIn and used them to craft personalized phishing emails. The emails contained a link to a fake login page that captured credentials. The analyst needs to categorize the harvesting of email addresses and the crafting of the phishing emails into the correct kill chain phases. Which two phases should the analyst assign?
Select an answer first - 20
A security analyst is documenting an attack where the attacker sent a malicious PDF attachment via email. The PDF exploited a reader vulnerability and installed a backdoor. The backdoor then phoned home to a C2 server. Which phase of the Cyber Kill Chain is the 'phoning home' activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.