350-201 · Question #37
Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it…
The correct answer is D. compromised network. Newly created privileged Active Directory accounts whose timestamps align with suspicious traffic originating from the internal network indicates an attacker has established a foothold inside the network and is creating persistence mechanisms.
Question
Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?
Exhibit
Options
- Acompromised insider
- Bcompromised root access
- Ccompromised database tables
- Dcompromised network
How the community answered
(34 responses)- A9% (3)
- B6% (2)
- C18% (6)
- D68% (23)
Why each option
Newly created privileged Active Directory accounts whose timestamps align with suspicious traffic originating from the internal network indicates an attacker has established a foothold inside the network and is creating persistence mechanisms.
A compromised insider implies a malicious or coerced employee acting deliberately from within; the indicators here - particularly the network traffic pattern - suggest an external attacker who has penetrated the environment rather than a trusted user.
Compromised root access describes unauthorized control of a specific root or admin account on a single host, whereas this scenario shows broad network activity and multiple new accounts being created.
Compromised database tables refers to unauthorized modification or exfiltration of database records, which is not supported by the evidence of new AD accounts and suspicious internal network traffic.
The combination of anomalous internal network traffic and privileged backdoor accounts created at the same time is a hallmark of a network-level compromise - an external threat actor has breached the network perimeter, moved laterally, and is creating rogue privileged accounts to maintain persistent access, which is broader than a single endpoint or account compromise and points to the network as the compromised layer.
Concept tested: Identifying network compromise via Active Directory indicators
Source: https://attack.mitre.org/techniques/T1136/
Topics
Community Discussion
No community discussion yet for this question.
