An attacker has targeted an organization in order to steal specific information. The attacker has found that the organization’s defenses are strong and that very few phishing messages arrive at end-user inboxes. The attacker has decided to try a watering hole attack. What first steps should the hacker use to ensure a successful watering hole attack?

🎲 Try a Random Question  |  Total Questions in Quiz: 82  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
CISA Domain 5: Protection of Information Asset — practice the complete quiz, review flashcards, or try a random question.


An attacker has targeted an organization in order to steal specific information. The attacker has found that the organization’s defenses are strong and that very few phishing messages arrive at end-user inboxes. The attacker has decided to try a watering hole attack. What first steps should the hacker use to ensure a successful watering hole attack?