CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
During incident investigation, an analyst notes that an attacker on a compromised finance workstation ran the following commands moments before proxy logs showed a large outbound transfer: `rar.exe a -hp secret.rar C:\Finance\Q4_Reports\*` `14:22:05 POST https://transfer.example-cloud.net/upload HTTP/1.1 200 [bytes-out: 512MB]` Which MITRE ATT&CK tactic best describes the proxy log entry showing the 512MB upload?
- AExfiltration
- BImpact
- CCollection
- DCommand and Control
Show answer & explanationAnswer & explanation
Correct answer: A. Exfiltration
The archive was already staged (Collection), and the large outbound POST transferring that archive to an external cloud storage endpoint represents the Exfiltration tactic — moving stolen data out of the network. Command and Control refers to the communication channel itself, not the act of removing data.
Why the other options are wrong
- B. Impact involves destructive or disruptive actions like data destruction, not data theft.
- C. Collection (creating the RAR archive) already occurred in the prior command; the log shown is the transfer, not the gathering step.
- D. C2 describes the attacker's control channel, not the data transfer of stolen files.
MITRE ATT&CK: Exfiltration
The Exfiltration tactic covers techniques attackers use to steal data from a network, often via C2 channels, cloud storage, or physical media.
- Follows Collection in typical attack flow
- Includes techniques like Exfiltration Over Web Service
- Large or anomalous outbound transfers are key indicators
Memory trick: Collect the loot, Control the line, then Exfiltrate it out, finally cause Impact