Beth is using the Cyber Kill Chain approach to analyzing the actions of an intruder on her network. She finds evidence that the most recent activity of the attacker was to successfully use a buffer overflow attack to gain control of a system. What stage is the attacker in?

A. Attacker in exploitation
B. Weaponization
C. Command and Control
D. Installation

Correct Answer: A

The stages of the Cyber Kill Chain are reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, and actions on objectives. The exploitation stage is where the attacker exploits a vulnerability to execute code on the victim’s system. That is the stage where a buffer overflow attack gains control of a system.

