nerdexam
Fortinet

NSE7_SOC_AR-7.6 · Question #19

Review the following incident report: The RAT provided the attackers with remote access and a foothold in the compromised system. Which two MITRE ATT&CK tactics does this incident report capture?…

The correct answer is A. Initial Access D. Persistence. Initial Access: The attackers used a phishing email (T1566) to trick an employee into executing a malicious link, which is a classic Initial Access tactic. Persistence: Installing a Remote Access Trojan to maintain a foothold on the compromised system aligns with the…

SOC Best Practices and Incident Response

Question

Review the following incident report:

The RAT provided the attackers with remote access and a foothold in the compromised system. Which two MITRE ATT&CK tactics does this incident report capture? (Choose two.)

Exhibit

NSE7_SOC_AR-7.6 question #19 exhibit

Options

  • AInitial Access
  • BDefense Evasion
  • CLateral Movement
  • DPersistence

How the community answered

(45 responses)
  • A
    71% (32)
  • B
    9% (4)
  • C
    20% (9)

Explanation

Initial Access: The attackers used a phishing email (T1566) to trick an employee into executing a malicious link, which is a classic Initial Access tactic. Persistence: Installing a Remote Access Trojan to maintain a foothold on the compromised system aligns with the Persistence tactic.

Topics

#MITRE ATT&CK tactics#Initial Access#Persistence#RAT malware

Community Discussion

No community discussion yet for this question.

Full NSE7_SOC_AR-7.6 Practice