exam questions

Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Exam 350-201 topic 1 question 8 discussion

Actual exam question from Cisco's 350-201
Question #: 8
Topic #: 1
[All 350-201 Questions]


Refer to the exhibit. At which stage of the threat kill chain is an attacker, based on these URIs of inbound web requests from known malicious Internet scanners?

  • A. exploitation
  • B. actions on objectives
  • C. delivery
  • D. reconnaissance
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://www2.deloitte.com/content/dam/Deloitte/sg/Documents/risk/sea-risk-cyber-101-july2017.pdf

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
corruptbits
10 months ago
Selected Answer: A
this is exploiting a vulnerability on the server to XSS and access sensitive files such as password file
upvoted 1 times
...
jaciro11
2 years ago
Its recon, he is trying to exploit multiples vulnerabilities which can exploit or not, after that the weaponization comes and the delivery can start, so this is a Recon.
upvoted 2 times
...
jay_c_an
2 years, 1 month ago
This is invoking command so either C2 or recon.
upvoted 1 times
jay_c_an
2 years, 1 month ago
Recon or action. More on action.
upvoted 1 times
...
...
DrVoIP
2 years, 2 months ago
Based on the URIs of inbound web requests from known malicious Internet scanners, the attacker is likely in the reconnaissance stage of the threat kill chain. The URIs "/invoker/JMXInvokerServlet" and "/CFIDE/adminapi" are commonly targeted by attackers during reconnaissance to identify potential vulnerabilities in web servers and applications. These URIs suggest that the attacker is attempting to identify systems that are running vulnerable versions of Apache Struts and ColdFusion, respectively.
upvoted 3 times
...
TOLU1985
2 years, 7 months ago
Selected Answer: C
/?a=<script>alert%28%22XSS%22%29%3B</script>&b=UNION+SELECT+ALL+FROM+information_schema+AND+%27+or+SLEEP%285%29+or%27&c=../../../../etc/passwd C or A not sure.
upvoted 1 times
TOLU1985
2 years, 7 months ago
It is XSS delivery , C is correct.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...