exam questions

Exam 312-39v2 All Questions

View all questions & answers for the 312-39v2 exam

Exam 312-39v2 topic 1 question 91 discussion

Actual exam question from ECCouncil's 312-39v2
Question #: 91
Topic #: 1
[All 312-39v2 Questions]

You are a Threat Hunter in the SOC team of a prestigious law firm specializing in high-profile corporate cases. Your firm has recently suffered a data breach, where confidential client documents were leaked on a dark web forum. As part of your proactive threat-hunting initiative, you analyze security logs, network traffic, and endpoint activity to trace the attacker’s steps using the Cyber Kill Chain framework. Your investigation reveals that the attacker initially bypassed the firm’s multi-factor authentication (MFA) by masquerading as a legitimate user. Once inside, they moved laterally within the internal network, accessed sensitive client records from a shared file repository, and exfiltrated the data over an extended period. You are tasked to identify the attack phase within the Cyber Kill Chain framework to strengthen defenses against similar attacks. Implement proactive threat hunting measures to detect future intrusions before data exfiltration occurs. At which Cyber Kill Chain phase was the attack identified?

  • A. Actions on Objectives
  • B. Delivery
  • C. Command & Control (C2)
  • D. Exploitation
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
trishaval
4 days, 1 hour ago
Selected Answer: A
the answer is Actions on objectives
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...