A disgruntled open-source developer has decided to sabotage a code repository with a logic bomb that will act as a wiper. Which of the following parts of the Cyber Kill Chain does this act exhibit?
Weaponization is the stage of the Cyber Kill Chain where the attacker creates or modifies a malicious payload to use against a target. In this case, the disgruntled open-source developer has created a logic bomb that will act as a wiper, which is a type of malware that destroys data on a system. This is an example of weaponization, as the developer has prepared a cyberweapon to sabotage the code repository.
Cyber Kill Chain | Lockheed Martin, which states: ''In the weaponization step, the adversary creates remote access malware weapon, such as a virus or worm, tailored to one or more vulnerabilities.''
The Cyber Kill Chain: The Seven Steps of a Cyberattack - EC-Council, which states: ''In the weaponization stage, all of the attacker's preparatory work culminates in the creation of malware to be used against an identified target.''
What is the Cyber Kill Chain? Introduction Guide - CrowdStrike, which states: ''Weaponization: The attacker creates a malicious payload that will be delivered to the target.''
A Chief Information Security Officer (CISO) is concerned that a specific threat actor who is known to target the company's business type may be able to breach the network and remain inside of it for an extended period of time.
Which of the following techniques should be performed to meet the CISO's goals?
The correct answer is B. Adversary emulation.
Adversary emulation is a technique that involves mimicking the tactics, techniques, and procedures (TTPs) of a specific threat actor or group to test the effectiveness of the security controls and incident response capabilities of an organization1. Adversary emulation can help identify and address the gaps and weaknesses in the security posture of an organization, as well as improve the readiness and skills of the security team. Adversary emulation can also help measure the dwell time, which is the duration that a threat actor remains undetected inside the network2.
The other options are not the best techniques to meet the CISO's goals. Vulnerability scanning (A) is a technique that involves scanning the network and systems for known vulnerabilities, but it does not simulate a real attack or test the incident response capabilities. Passive discovery is a technique that involves collecting information about the network and systems without sending any packets or probes, but it does not identify or exploit any vulnerabilities or test the security controls. Bug bounty (D) is a program that involves rewarding external researchers or hackers for finding and reporting vulnerabilities in an organization's systems or applications, but it does not focus on a specific threat actor or group.
A security analyst noticed the following entry on a web server log:
Warning: fopen (http://127.0.0.1:16) : failed to open stream:
Connection refused in /hj/var/www/showimage.php on line 7
Which of the following malicious activities was most likely attempted?
The malicious activity that was most likely attempted is SSRF (Server-Side Request Forgery). This is a type of attack that exploits a vulnerable web application to make requests to other resources on behalf of the web server. In this case, the attacker tried to use the fopen function to access the local loopback address (127.0.0.1) on port 16, which could be a service that is not intended to be exposed to the public. The connection was refused, indicating that the port was closed or filtered. Reference: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 2: Software and Application Security, page 66.
Which of the following best describes the importance of implementing TAXII as part of a threat intelligence program?
The correct answer is B. It proactively facilitates real-time information sharing between the public and private sectors.
TAXII, or Trusted Automated eXchange of Intelligence Information, is a standard protocol for sharing cyber threat intelligence in a standardized, automated, and secure manner. TAXII defines how cyber threat information can be shared via services and message exchanges, such as discovery, collection management, inbox, and poll. TAXII is designed to support STIX, or Structured Threat Information eXpression, which is a standardized language for describing cyber threat information in a readable and consistent format. Together, STIX and TAXII form a framework for sharing and using threat intelligence, creating an open-source platform that allows users to search through records containing attack vectors details such as malicious IP addresses, malware signatures, and threat actors123.
The importance of implementing TAXII as part of a threat intelligence program is that it proactively facilitates real-time information sharing between the public and private sectors. By using TAXII, organizations can exchange cyber threat information with various entities, such as security vendors, government agencies, industry associations, or trusted groups. TAXII enables different sharing models, such as hub and spoke, source/subscriber, or peer-to-peer, depending on the needs and preferences of the information producers and consumers. TAXII also supports different levels of access control, encryption, and authentication to ensure the security and privacy of the shared information123.
By implementing TAXII as part of a threat intelligence program, organizations can benefit from the following advantages:
They can receive timely and relevant information about the latest threats and vulnerabilities that may affect their systems or networks.
They can leverage the collective knowledge and experience of other organizations that have faced similar or related threats.
They can improve their situational awareness and threat detection capabilities by correlating and analyzing the shared information.
They can enhance their incident response and mitigation strategies by applying the best practices and recommendations from the shared information.
They can contribute to the overall improvement of cyber security by sharing their own insights and feedback with other organizations123.
The other options are incorrect because they do not accurately describe the importance of implementing TAXII as part of a threat intelligence program.
Option A is incorrect because TAXII does not provide a structured way to gain information about insider threats. Insider threats are malicious activities conducted by authorized users within an organization, such as employees, contractors, or partners. Insider threats can be detected by using various methods, such as user behavior analysis, data loss prevention, or anomaly detection. However, TAXII is not designed to collect or share information about insider threats specifically. TAXII is more focused on external threats that originate from outside sources, such as hackers, cybercriminals, or nation-states4.
Option C is incorrect because TAXII does not exchange messages in the most cost-effective way and requires little maintenance once implemented. TAXII is a protocol that defines how messages are exchanged, but it does not specify the cost or maintenance of the exchange. The cost and maintenance of implementing TAXII depend on various factors, such as the type and number of services used, the volume and frequency of data exchanged, the security and reliability requirements of the exchange, and the availability and compatibility of existing tools and platforms. Implementing TAXII may require significant resources and efforts from both the information producers and consumers to ensure its functionality and performance5.
Option D is incorrect because TAXII is not a semi-automated solution to gather threat intelligence about competitors in the same sector. TAXII is a fully automated solution that enables the exchange of threat intelligence among various entities across different sectors. TAXII does not target or collect information about specific competitors in the same sector. Rather, it aims to foster collaboration and cooperation among organizations that share common interests or goals in cyber security. Moreover, gathering threat intelligence about competitors in the same sector may raise ethical and legal issues that are beyond the scope of TAXII.
1 What is STIX/TAXII? | Cloudflare
2 What Are STIX/TAXII Standards? - Anomali Resources
3 What is STIX and TAXII? - EclecticIQ
4 What Is an Insider Threat? Definition & Examples | Varonis
5 Implementing STIX/TAXII - GitHub Pages
[6] Cyber Threat Intelligence: Ethical Hacking vs Unethical Hacking | Infosec
A cryptocurrency service company is primarily concerned with ensuring the accuracy of the data on one of its systems. A security analyst has been tasked with prioritizing vulnerabilities for remediation for the system. The analyst will use the following CVSSv3.1 impact metrics for prioritization:

Which of the following vulnerabilities should be prioritized for remediation?
Vulnerability 2 has the highest impact metrics, specifically the highest attack vector (AV) and attack complexity (AC) values. This means that the vulnerability is more likely to be exploited and more difficult to remediate.
CVSS v3.1 Specification Document, section 2.1.1 and 2.1.2
The CVSS v3 Vulnerability Scoring System, section 3.1 and 3.2
Susan Evans
16 days agoJames Bell
2 months agoDennis Brown
3 months agoVulnerability Management Anderson
3 months agoSecurity Operations Taylor
2 months agoThreat Intelligence Johnson
2 months agoElizabeth Nelson
4 months agoVulnerability Management Garcia
4 months agoSecurity Operations Brown
3 months agoKevin Murphy
5 months agoMelissa Wright
4 months agoJason Wright
4 months agoStephanie Collins
4 months agoJohn Stewart
4 months agoElizabeth Flores
4 months agoChanel
5 months agoColene
5 months agoJustine
5 months agoCarey
6 months agoMaurine
6 months agoErick
7 months agoMalinda
7 months agoReita
7 months agoPhyliss
7 months agoJaclyn
8 months agoMaurine
8 months agoHelene
8 months agoGeraldine
8 months agoMilly
9 months agoWilda
9 months agoMicheline
9 months agoAileen
9 months agoTeddy
9 months agoLuther
10 months agoJunita
10 months agoLazaro
10 months agoWava
11 months agoFreeman
11 months agoDominga
11 months agoLouvenia
11 months agoDelisa
12 months agoColby
12 months agoLeota
1 year agoHyman
1 year agoTheola
1 year agoArthur
1 year agoMa
1 year agoLashon
1 year agoSamira
1 year agoJoanna
1 year agoDelfina
1 year agoBilli
1 year agoRex
1 year agoKris
1 year agoDomitila
1 year agoJamal
2 years agoVivan
2 years agoMartina
2 years agoWerner
2 years agoLynelle
2 years agoMichal
2 years agoDesiree
2 years agoAnnamae
2 years agoValda
2 years agoMarshall
2 years agoKatheryn
2 years agoStanford
2 years agoLaurel
2 years agoPortia
2 years agoErin
2 years agoTamala
2 years agoEdison
2 years agoJohnetta
2 years agoCletus
2 years agoTheodora
2 years agoCora
2 years agoWillow
2 years agoRikki
2 years agoMelissa
2 years agoLavonna
2 years agoDerrick
2 years agoCristen
2 years agoHillary
2 years agoCasie
2 years agoArmando
2 years agoAshanti
2 years agoAileen
2 years agoAlberto
2 years agoNovella
2 years agoCarlee
2 years agoCristen
2 years agoBrandon
2 years agofelvaa
2 years agoalexa
2 years agoNathon
2 years agomelvin
2 years agoMark james
2 years agoAmmie
2 years ago