A SOC analyst is mapping an insider data-theft case to the Cyber Kill Chain. The user already had valid credentials and access, so no phishing, malware, or perimeter breach was observed. Why does the framework underrepresent this activity?
Select an answer to reveal the explanation.
Short Explanation
Think of the Cyber Kill Chain like a castle tour: it starts with scouts outside the walls. If the attacker is already inside wearing a badge, that tour skips most of the story. You shouldn't force insider cases into early breach stages — the framework assumes an outside-to-inside sequence.
Full Explanation
The Cyber Kill Chain models an attack as a linear sequence that normally begins with reconnaissance and ends with actions on objectives, so its early phases presume an adversary must first discover, weaponize, deliver, and exploit before gaining a foothold. When the actor is already an authorized insider, those preliminary stages may never occur, and the framework can make the event look shorter or missing than it actually is. A requirement for full MITRE ATT&CK mapping is not the limitation, because the two models are separate and can be used together without one validating the other. A missing command-and-control phase is also incorrect, since the Cyber Kill Chain explicitly includes command and control after installation. Inability to represent exfiltration is likewise wrong, because actions on objectives covers data theft, destruction, or other final effects. Exam caveat: CompTIA expects you to know that framework limitations come from the model's assumptions, not from a single missing phase. Operational check: map the observed insider actions to ATT&CK tactics and then compare them with Cyber Kill Chain phases to document where the framework omits pre-breach steps.