アナリストは、企業ネットワークの外側にある IP アドレスが、外部に面した資産全体のネットワークおよび脆弱性スキャンを実行するために使用されていることに気づきました。アナリストが目撃している攻撃フレームワークの次のステップはどれですか?
正解:B
Reconnaissance is the first stage in the Cyber Kill Chain and involves researching potential targets before carrying out any penetration testing. The reconnaissance stage may include identifying potential targets, finding their vulnerabilities, discovering which third parties are connected to them (and what data they can access), and exploring existing entry points as well as finding new ones. Reconnaissance can take place both online and offline. In this case, an analyst finds that an IP address outside of the company network is being used to run network and vulnerability scans across external-facing assets. This indicates that the analyst is witnessing reconnaissance activity by an attacker. Official References: https://www.lockheedmartin.com/en-us /capabilities/cyber/cyber-kill-chain.html