1
00:00:06,600 --> 00:00:09,240
- So welcome to lesson
eight, deep dive quiz.

2
00:00:09,240 --> 00:00:12,120
The lesson eight was all
about, given a scenario,

3
00:00:12,120 --> 00:00:14,820
analyze indicators of malicious activity.

4
00:00:14,820 --> 00:00:17,670
And we looked at all kinds
of malicious activity.

5
00:00:17,670 --> 00:00:19,650
We started in lesson
8.1 one of saying, okay,

6
00:00:19,650 --> 00:00:21,330
well what is an indicator?

7
00:00:21,330 --> 00:00:23,640
And then in 8.2, we
looked at malware attacks.

8
00:00:23,640 --> 00:00:25,800
In 8.3, brute force attacks,

9
00:00:25,800 --> 00:00:28,230
8.4 digital infrastructure attacks,

10
00:00:28,230 --> 00:00:32,310
8.5 application attacks,
8.6 wireless attacks.

11
00:00:32,310 --> 00:00:35,970
And lastly, in 8.7 cryptographic attacks.

12
00:00:35,970 --> 00:00:39,150
All with the goal that if
you are given a scenario

13
00:00:39,150 --> 00:00:43,080
you could analyze the indicators
of the malicious activity.

14
00:00:43,080 --> 00:00:45,420
So now together, let's do 10 questions.

15
00:00:45,420 --> 00:00:48,390
Make sure you've got a pen or
a pencil and a piece of paper.

16
00:00:48,390 --> 00:00:51,030
Keep putting me on pause so
you can answer the question

17
00:00:51,030 --> 00:00:54,690
and take me off pause and
come back and hear the answer.

18
00:00:54,690 --> 00:00:55,800
So let's start our quiz.

19
00:00:55,800 --> 00:00:57,933
Ready, 1, 2, 3, let's go.

20
00:00:59,081 --> 00:01:02,640
The first thing we're gonna do
is match the attack category

21
00:01:02,640 --> 00:01:04,080
and the description.

22
00:01:04,080 --> 00:01:06,120
So the attack categories
on the left hand side.

23
00:01:06,120 --> 00:01:09,240
Denial of service,
hijacking, web hijacking,

24
00:01:09,240 --> 00:01:11,400
poisoning, and spoofing.

25
00:01:11,400 --> 00:01:13,410
On the right hand side,
we have our descriptions.

26
00:01:13,410 --> 00:01:17,640
Intercepting and manipulating
communication, misdirection,

27
00:01:17,640 --> 00:01:20,580
impersonating an address,
system or person,

28
00:01:20,580 --> 00:01:22,470
overwhelming system resources,

29
00:01:22,470 --> 00:01:25,260
manipulating a trusted source of data.

30
00:01:25,260 --> 00:01:28,530
Great time to put me on pause
so you can match them up.

31
00:01:28,530 --> 00:01:30,300
All right, well, I'm gonna
start right up on the top.

32
00:01:30,300 --> 00:01:31,200
Denial of service.

33
00:01:31,200 --> 00:01:34,170
And if I look through my
list, I'm gonna choose

34
00:01:34,170 --> 00:01:37,986
overwhelming system resources
as a denial of service.

35
00:01:37,986 --> 00:01:41,130
Now, 'cause I've got
hijacking and if I look

36
00:01:41,130 --> 00:01:44,520
through my list, that's
going to be intercepting.

37
00:01:44,520 --> 00:01:46,470
So I'm gonna hijack or intercept

38
00:01:46,470 --> 00:01:49,170
and manipulating communications.

39
00:01:49,170 --> 00:01:51,453
Then I have web hijacking.

40
00:01:52,530 --> 00:01:56,130
Now, what does web
hijacking usually result in?

41
00:01:56,130 --> 00:01:58,950
Well, web hijacking,
right, usually results

42
00:01:58,950 --> 00:02:01,350
in misdirection, right?

43
00:02:01,350 --> 00:02:06,072
Misdirection to another
domain or another location.

44
00:02:06,072 --> 00:02:08,760
Then we've got poisoning and spoofing.

45
00:02:08,760 --> 00:02:10,500
So what's the difference?

46
00:02:10,500 --> 00:02:12,990
Well, poisoning is
going to be manipulating

47
00:02:12,990 --> 00:02:16,590
a trusted source of
data, like DNS zone files

48
00:02:16,590 --> 00:02:19,440
or a routing table or an arp cache.

49
00:02:19,440 --> 00:02:23,760
And spoofing is impersonating an address,

50
00:02:23,760 --> 00:02:26,460
a system or a person.

51
00:02:26,460 --> 00:02:28,980
So denial of service,
overwhelming system resources.

52
00:02:28,980 --> 00:02:32,190
Hijacking, intercepting and
manipulating communications.

53
00:02:32,190 --> 00:02:33,900
Web hijacking, misdirection.

54
00:02:33,900 --> 00:02:36,360
Poisoning, manipulating
a trusted source of data

55
00:02:36,360 --> 00:02:38,953
and spoofing, impersonating an address,

56
00:02:38,953 --> 00:02:41,100
a system or a person.

57
00:02:41,100 --> 00:02:42,360
Do you like it, do you agree?

58
00:02:42,360 --> 00:02:44,970
We'll check and that's correct.

59
00:02:44,970 --> 00:02:46,830
All right, let's go to number two.

60
00:02:46,830 --> 00:02:49,680
To everyone's surprise, on December 31st,

61
00:02:49,680 --> 00:02:51,630
a software application appeared

62
00:02:51,630 --> 00:02:54,300
to intentionally self-destruct.

63
00:02:54,300 --> 00:02:56,280
So everybody's gone for the day probably,

64
00:02:56,280 --> 00:02:58,470
it's New Year's Eve, it's time to party.

65
00:02:58,470 --> 00:03:00,930
And all of a sudden this
software application

66
00:03:00,930 --> 00:03:03,270
intentionally self-destructs.

67
00:03:03,270 --> 00:03:05,310
What's the most likely cause?

68
00:03:05,310 --> 00:03:10,310
A logic bomb, bloatware,
ransomware, or a backdoor?

69
00:03:11,580 --> 00:03:14,973
Remember, it's happening at a
specific time, December 31st.

70
00:03:15,960 --> 00:03:16,793
What are you gonna choose?

71
00:03:16,793 --> 00:03:20,253
Logic bomb, bloatware,
ransomware, or a backdoor?

72
00:03:21,780 --> 00:03:24,270
Well, I'm gonna choose logic bomb.

73
00:03:24,270 --> 00:03:27,780
Logic bomb because it
happened at a particular time.

74
00:03:27,780 --> 00:03:30,300
Bloatware is the unwanted applications,

75
00:03:30,300 --> 00:03:32,040
potentially unwanted applications.

76
00:03:32,040 --> 00:03:34,860
Ransomware would encrypt
our files, not destroy them.

77
00:03:34,860 --> 00:03:37,470
And a backdoor, well,
would be when someone gets

78
00:03:37,470 --> 00:03:40,590
into our application and that's
not happening here, right?

79
00:03:40,590 --> 00:03:44,130
The application appeared to
intentionally self-destruct.

80
00:03:44,130 --> 00:03:45,690
I'm betting on a logic bomb.

81
00:03:45,690 --> 00:03:47,973
Let's check it and that's correct.

82
00:03:49,620 --> 00:03:50,610
Question three.

83
00:03:50,610 --> 00:03:52,590
An adversary was able to authenticate

84
00:03:52,590 --> 00:03:54,900
to a consumer online banking system

85
00:03:54,900 --> 00:03:57,510
using multiple customer credentials.

86
00:03:57,510 --> 00:03:59,910
Every time, every single time,

87
00:03:59,910 --> 00:04:02,820
they had the correct
username and password.

88
00:04:02,820 --> 00:04:04,740
So what's the most likely method used

89
00:04:04,740 --> 00:04:06,453
for discovering the credentials?

90
00:04:07,590 --> 00:04:12,030
Dictionary, rainbow table,
basic discovery attack

91
00:04:12,030 --> 00:04:13,890
and informed.

92
00:04:13,890 --> 00:04:16,141
So every time they had a right username

93
00:04:16,141 --> 00:04:19,680
they seemed to have the
right password as well.

94
00:04:19,680 --> 00:04:21,480
How did they do that?

95
00:04:21,480 --> 00:04:25,440
Dictionary, rainbow table,
basic discovery attack

96
00:04:25,440 --> 00:04:26,733
or informed?

97
00:04:29,820 --> 00:04:32,220
I'm gonna choose informed, right?

98
00:04:32,220 --> 00:04:33,690
Informed means that they already

99
00:04:33,690 --> 00:04:35,820
have a known good source, right?

100
00:04:35,820 --> 00:04:38,130
And they're using that known good source

101
00:04:38,130 --> 00:04:40,950
to attempt to get in, in this case,

102
00:04:40,950 --> 00:04:42,480
get into the banking system.

103
00:04:42,480 --> 00:04:43,980
So there it's informed.

104
00:04:43,980 --> 00:04:46,740
Dictionary would be using
common dictionary words.

105
00:04:46,740 --> 00:04:50,940
A rainbow table would be, you
know, we can have the hashes

106
00:04:50,940 --> 00:04:53,100
and the passwords that
come from a rainbow table.

107
00:04:53,100 --> 00:04:55,680
Basic discovery attack is
using everything, right?

108
00:04:55,680 --> 00:04:57,750
So both, you know, dictionary, rainbow

109
00:04:57,750 --> 00:05:00,900
and basic attack are
probably going to result

110
00:05:00,900 --> 00:05:05,220
in a lot of false credentials,
but informed, wow,

111
00:05:05,220 --> 00:05:07,290
they've got the information.

112
00:05:07,290 --> 00:05:09,543
Let's try it and that would be correct.

113
00:05:11,310 --> 00:05:12,540
So question four.

114
00:05:12,540 --> 00:05:16,230
We're gonna choose a correct
choice in each dropdown list.

115
00:05:16,230 --> 00:05:17,820
First, I'm gonna read you the questions

116
00:05:17,820 --> 00:05:19,500
'cause maybe you just
already know the answer.

117
00:05:19,500 --> 00:05:21,570
Then we'll come back and
we'll look at our choices.

118
00:05:21,570 --> 00:05:24,030
Malicious code whose primary
function is to replicate

119
00:05:24,030 --> 00:05:25,770
and deliver its payload.

120
00:05:25,770 --> 00:05:28,200
A clandestine program designed to provide

121
00:05:28,200 --> 00:05:30,510
continued privileged access.

122
00:05:30,510 --> 00:05:34,170
A malware technique that evades
pattern matching detection

123
00:05:34,170 --> 00:05:37,260
by frequently changing
identifiable characteristics

124
00:05:37,260 --> 00:05:40,320
and malicious code that
appears legitimate.

125
00:05:40,320 --> 00:05:41,850
Now hopefully you know
what all of those are,

126
00:05:41,850 --> 00:05:43,200
but let's go through our dropdowns

127
00:05:43,200 --> 00:05:44,650
and see what our choices are.

128
00:05:45,570 --> 00:05:48,240
Malicious code whose primary
function is to replicate

129
00:05:48,240 --> 00:05:49,740
and deliver its payload.

130
00:05:49,740 --> 00:05:54,720
Is that a rootkit, a
virus, a worm, or a Trojan?

131
00:05:54,720 --> 00:05:56,020
What are you gonna select?

132
00:05:56,970 --> 00:05:58,443
Well, I'm gonna choose virus.

133
00:05:59,310 --> 00:06:01,350
The next is a clandestine program designed

134
00:06:01,350 --> 00:06:04,462
to provide continued privileged access.

135
00:06:04,462 --> 00:06:09,462
Programmatic, injection,
spyware, or a rootkit?

136
00:06:11,370 --> 00:06:13,590
Provide continued privileged access.

137
00:06:13,590 --> 00:06:16,110
Privilege is a really important word here.

138
00:06:16,110 --> 00:06:17,763
I'm gonna go with rootkit.

139
00:06:19,320 --> 00:06:20,790
Our next one is malware technique

140
00:06:20,790 --> 00:06:22,560
that evades pattern matching detection

141
00:06:22,560 --> 00:06:25,980
by frequently changing
identifiable characteristics.

142
00:06:25,980 --> 00:06:30,060
Metamorphic, armored,
stealth or polymorphic?

143
00:06:30,060 --> 00:06:31,500
Now what's really common to confuse

144
00:06:31,500 --> 00:06:33,300
metamorphic and polymorphic.

145
00:06:33,300 --> 00:06:35,970
Polymorphic is when
characteristics are changed.

146
00:06:35,970 --> 00:06:39,960
Metamorphic is when we
have a whole new piece

147
00:06:39,960 --> 00:06:42,090
of malware with every single iteration.

148
00:06:42,090 --> 00:06:45,240
So in this case, I'm
gonna choose polymorphic.

149
00:06:45,240 --> 00:06:48,960
And lastly, malicious code
that appears legitimate.

150
00:06:48,960 --> 00:06:53,520
Is this programmatic,
Trojan, a virus or a worm?

151
00:06:53,520 --> 00:06:54,630
So it appears to be fine.

152
00:06:54,630 --> 00:06:56,700
It appears like it's a music file

153
00:06:56,700 --> 00:06:58,710
or it's a game, or it's a picture.

154
00:06:58,710 --> 00:06:59,940
What is it?

155
00:06:59,940 --> 00:07:01,500
I'm gonna choose Trojan.

156
00:07:01,500 --> 00:07:03,870
So malicious code whose primary
function is to replicate

157
00:07:03,870 --> 00:07:05,670
and deliver its payload, a virus.

158
00:07:05,670 --> 00:07:07,140
A clandestine program designed

159
00:07:07,140 --> 00:07:10,020
to provide continued
privilege access, a rootkit.

160
00:07:10,020 --> 00:07:13,821
Malware technique that
evades pattern matching

161
00:07:13,821 --> 00:07:17,447
detection by frequently
changing its identifiable

162
00:07:17,447 --> 00:07:19,710
characteristic, polymorphic.

163
00:07:19,710 --> 00:07:24,710
And malicious code that
appears legitimate, a Trojan.

164
00:07:24,750 --> 00:07:25,770
You agree?

165
00:07:25,770 --> 00:07:28,020
Let's try it and that's correct.

166
00:07:28,020 --> 00:07:30,360
All right, let's move on to question five.

167
00:07:30,360 --> 00:07:33,870
SSL is considered deprecated
and has been replaced with TLS.

168
00:07:33,870 --> 00:07:36,480
However many servers
still have SSL enabled

169
00:07:36,480 --> 00:07:38,730
for backward compatibility.

170
00:07:38,730 --> 00:07:39,960
Is this a problem?

171
00:07:39,960 --> 00:07:41,970
All right, everybody's
gonna get this one right.

172
00:07:41,970 --> 00:07:45,390
Not a problem because most
browsers only support TLS.

173
00:07:45,390 --> 00:07:47,700
This is a problem because
the attacker can force

174
00:07:47,700 --> 00:07:49,830
a downgrade to SSL.

175
00:07:49,830 --> 00:07:54,000
This is a problem because SSL
has more significant overhead

176
00:07:54,000 --> 00:07:58,290
or not a problem because TLS has priority.

177
00:07:58,290 --> 00:07:59,790
I know you're gonna get this right.

178
00:07:59,790 --> 00:08:01,170
We talked about this in the lesson.

179
00:08:01,170 --> 00:08:04,120
We talked about this in the
security and action case study.

180
00:08:05,220 --> 00:08:07,710
Not a problem, because most
browsers support only TLS.

181
00:08:07,710 --> 00:08:10,680
Well, it's true that most
browsers only support TLS now

182
00:08:10,680 --> 00:08:12,540
but that's not really relevant.

183
00:08:12,540 --> 00:08:14,550
Is a problem because an attacker can force

184
00:08:14,550 --> 00:08:15,870
a downgrade to SSL?

185
00:08:15,870 --> 00:08:18,570
Yeah, I think that's a big problem.

186
00:08:18,570 --> 00:08:21,540
Not a problem because SSL has
more significant overhead?

187
00:08:21,540 --> 00:08:23,040
That's not relevant.

188
00:08:23,040 --> 00:08:25,440
Not a problem because TLS has priority.

189
00:08:25,440 --> 00:08:26,670
Again, not relevant.

190
00:08:26,670 --> 00:08:30,660
If the attacker can
force a downgrade attack,

191
00:08:30,660 --> 00:08:31,800
it is a problem.

192
00:08:31,800 --> 00:08:35,370
Again, because the attacker
can force a downgrade attack.

193
00:08:35,370 --> 00:08:36,203
I hope you agree.

194
00:08:36,203 --> 00:08:38,763
Let's check it out and that's correct.

195
00:08:40,380 --> 00:08:41,640
All right, in this variation

196
00:08:41,640 --> 00:08:43,380
of a cross-site scripting attack,

197
00:08:43,380 --> 00:08:47,970
the attacker injects a
malicious code into the webpage.

198
00:08:47,970 --> 00:08:52,970
Is this an XRSF, a persistent
XXS, cross-site scripting,

199
00:08:53,670 --> 00:08:56,070
a client side cross-site scripting,

200
00:08:56,070 --> 00:08:58,623
or a reflective cross site scripting?

201
00:09:00,180 --> 00:09:03,390
So only two of these are
really cross site scripting

202
00:09:03,390 --> 00:09:06,120
types of attacks we've
talked about, and only one

203
00:09:06,120 --> 00:09:07,830
of them is gonna be the correct answer.

204
00:09:07,830 --> 00:09:10,860
So cut start using that
process of elimination.

205
00:09:10,860 --> 00:09:14,460
In this case, the attacker
injects the malicious code

206
00:09:14,460 --> 00:09:16,140
into the webpage.

207
00:09:16,140 --> 00:09:21,140
Persistent, client side,
reflective or XRSF?

208
00:09:23,293 --> 00:09:24,443
What are you gonna choose?

209
00:09:25,980 --> 00:09:27,870
I'm gonna choose persistent.

210
00:09:27,870 --> 00:09:30,720
In a persistent cross-site
scripting attack, right,

211
00:09:30,720 --> 00:09:34,920
the malicious code is in the
webpage and so every time

212
00:09:34,920 --> 00:09:37,590
someone visits that
webpage there's a potential

213
00:09:37,590 --> 00:09:40,140
that they're gonna be
ultimately compromised.

214
00:09:40,140 --> 00:09:42,120
Reflective cross-site scripting

215
00:09:42,120 --> 00:09:44,010
which is the other one
that we talked about

216
00:09:44,010 --> 00:09:48,330
is when the script starts
at the client side,

217
00:09:48,330 --> 00:09:49,950
gets injected into the website

218
00:09:49,950 --> 00:09:52,860
and it's reflected back to the client.

219
00:09:52,860 --> 00:09:54,360
So persistent is the one I like.

220
00:09:54,360 --> 00:09:55,193
Hopefully you do, too.

221
00:09:55,193 --> 00:09:58,053
Let's check it out and that's correct.

222
00:09:59,370 --> 00:10:00,840
Question seven.

223
00:10:00,840 --> 00:10:03,810
Which of the following artifacts
is a distributed denial

224
00:10:03,810 --> 00:10:08,810
of service or DDoS IOC,
indicator of compromise?

225
00:10:09,330 --> 00:10:12,210
Traffic volume, a virus signature,

226
00:10:12,210 --> 00:10:16,262
modified registry
settings or renamed files?

227
00:10:16,262 --> 00:10:19,050
So we're looking for an artifact, right?

228
00:10:19,050 --> 00:10:22,920
That is an IOC, right. an
indicator of compromise

229
00:10:22,920 --> 00:10:25,260
about a distributed
denial of service attack.

230
00:10:25,260 --> 00:10:27,450
So which one of these
makes the most sense?

231
00:10:27,450 --> 00:10:29,820
Traffic volume, virus signatures

232
00:10:29,820 --> 00:10:32,850
modified registry
setting, or renamed files.

233
00:10:32,850 --> 00:10:34,350
Go ahead and make that choice.

234
00:10:35,310 --> 00:10:36,750
I'm gonna choose traffic volume

235
00:10:36,750 --> 00:10:38,280
because a distributed denial of service

236
00:10:38,280 --> 00:10:40,170
is all about traffic, right?

237
00:10:40,170 --> 00:10:42,150
That's gonna be the most likely artifact

238
00:10:42,150 --> 00:10:44,280
that we're gonna look for in a distributed

239
00:10:44,280 --> 00:10:45,720
denial of service attack.

240
00:10:45,720 --> 00:10:47,100
You agree?

241
00:10:47,100 --> 00:10:48,933
Let's check and that is correct.

242
00:10:49,800 --> 00:10:51,210
All right, question eight.

243
00:10:51,210 --> 00:10:54,300
This technique best
prevents an injection attack

244
00:10:54,300 --> 00:10:56,670
from successfully executing.

245
00:10:56,670 --> 00:11:01,440
A bash script, time
synchronization, firewall filtering

246
00:11:01,440 --> 00:11:04,590
or input and output validation.

247
00:11:04,590 --> 00:11:07,290
Our goal is to prevent an injection attack

248
00:11:07,290 --> 00:11:09,093
from successfully executing.

249
00:11:09,930 --> 00:11:10,920
Which one do you like?

250
00:11:10,920 --> 00:11:14,490
Bash, time synchronization,
firewall filtering

251
00:11:14,490 --> 00:11:17,160
or input and output validation?

252
00:11:17,160 --> 00:11:18,990
There's one answer here that stands way

253
00:11:18,990 --> 00:11:22,560
out above the the rest, and
it's this one right here.

254
00:11:22,560 --> 00:11:24,720
Input and output validation, right?

255
00:11:24,720 --> 00:11:28,140
If we have input validation,
then we can't input any type

256
00:11:28,140 --> 00:11:31,590
of instructions that would
be executed by the processor.

257
00:11:31,590 --> 00:11:33,900
And output validation says
we're not gonna return

258
00:11:33,900 --> 00:11:37,413
anything that shouldn't be
returned back to the user.

259
00:11:38,610 --> 00:11:41,386
Let's check it out and it is correct.

260
00:11:41,386 --> 00:11:43,170
All right, question nine.

261
00:11:43,170 --> 00:11:45,330
We're gonna match the
following wireless attacks

262
00:11:45,330 --> 00:11:47,850
with the attack attribute and description.

263
00:11:47,850 --> 00:11:50,640
So on the left hand side
we have RFID eavesdropping,

264
00:11:50,640 --> 00:11:55,640
a replay attack, disassociation,
bluesnarfing and evil twin.

265
00:11:56,130 --> 00:11:57,720
And on the right hand
side, we have the type

266
00:11:57,720 --> 00:12:00,180
of attack and kind of
what's happening, right?

267
00:12:00,180 --> 00:12:03,570
Hijacking in this case, reusing
authentication credentials,

268
00:12:03,570 --> 00:12:05,220
access for authentication,

269
00:12:05,220 --> 00:12:09,120
spoofing for impersonation,
sniffing, doing packet capture

270
00:12:09,120 --> 00:12:12,630
and the denial of service
for deauthentication.

271
00:12:12,630 --> 00:12:14,490
So where should we start?

272
00:12:14,490 --> 00:12:17,160
Let's start with denial of
service and deauthentication.

273
00:12:17,160 --> 00:12:19,953
It's really a disassociation attack.

274
00:12:20,825 --> 00:12:23,100
Access and authentication.

275
00:12:23,100 --> 00:12:25,293
Oh, that's gonna be bluesnarfing for sure.

276
00:12:26,220 --> 00:12:27,570
A replay attack?

277
00:12:27,570 --> 00:12:28,890
Well, that would be hijacking

278
00:12:28,890 --> 00:12:31,923
and then reusing
authentication credentials.

279
00:12:36,570 --> 00:12:37,403
Let's see.

280
00:12:37,403 --> 00:12:40,260
And evil twin is impersonation
and spoofing, right?

281
00:12:40,260 --> 00:12:44,460
Impersonating a legitimate access point.

282
00:12:44,460 --> 00:12:49,460
And lastly, RFID eavesdropping,
sniffing and packet capture.

283
00:12:49,590 --> 00:12:52,950
So RFID eavesdropping,
sniffing and packet capture.

284
00:12:52,950 --> 00:12:56,280
Replay, hijacking or reusing
authentication credentials.

285
00:12:56,280 --> 00:13:00,270
Disassociation, denial of
service and deauthentication.

286
00:13:00,270 --> 00:13:02,610
Bluesnarfing, access and authentication,

287
00:13:02,610 --> 00:13:05,820
and evil twins, spoofing
and impersonation.

288
00:13:05,820 --> 00:13:10,560
Let's see how we did, fingers
crossed and it is correct.

289
00:13:10,560 --> 00:13:12,360
All right, here's our last question.

290
00:13:12,360 --> 00:13:14,190
I want you to put the first four steps

291
00:13:14,190 --> 00:13:17,010
in the cyber kill chain
in the correct order.

292
00:13:17,010 --> 00:13:18,570
Remember, we talked
about the Lockheed Martin

293
00:13:18,570 --> 00:13:19,650
cyber kill chain.

294
00:13:19,650 --> 00:13:21,630
I want you to put the first four steps

295
00:13:21,630 --> 00:13:23,130
in the correct order.

296
00:13:23,130 --> 00:13:25,650
Starting with number one,
what's the first thing

297
00:13:25,650 --> 00:13:27,870
that we're gonna have happen?

298
00:13:27,870 --> 00:13:30,849
Well, our attackers need to learn about us

299
00:13:30,849 --> 00:13:34,993
so we're gonna start with reconnaissance.

300
00:13:34,993 --> 00:13:39,273
Then we're going to have weaponization.

301
00:13:40,980 --> 00:13:43,450
Then we're going to deliver our weapon

302
00:13:44,430 --> 00:13:46,380
and then we'll exploit.

303
00:13:46,380 --> 00:13:50,487
Reconnaissance, weaponization,
delivery, exploit.

304
00:13:51,411 --> 00:13:52,860
Do you like it, you agree?

305
00:13:52,860 --> 00:13:54,900
All right, let's check it out.

306
00:13:54,900 --> 00:13:56,340
And that is correct.

307
00:13:56,340 --> 00:13:57,450
Awesome, you did great.

308
00:13:57,450 --> 00:14:00,600
10 questions is a lot of
material that we covered.

309
00:14:00,600 --> 00:14:04,110
You probably deserve a
break, but when you're ready

310
00:14:04,110 --> 00:14:06,750
we're gonna go to lesson nine,
which is explain the purpose

311
00:14:06,750 --> 00:14:10,320
of mitigation techniques used
to secure the enterprise.

312
00:14:10,320 --> 00:14:11,420
So I'll see you there.
