CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

During incident investigation, an analyst notes that an attacker on a compromised finance workstation ran the following commands moments before proxy logs showed a large outbound transfer: `rar.exe a -hp secret.rar C:\Finance\Q4_Reports\*` `14:22:05 POST https://transfer.example-cloud.net/upload HTTP/1.1 200 [bytes-out: 512MB]` Which MITRE ATT&CK tactic best describes the proxy log entry showing the 512MB upload?

  1. AExfiltration
  2. BImpact
  3. CCollection
  4. DCommand and Control
Show answer & explanation

Correct answer: A. Exfiltration

The archive was already staged (Collection), and the large outbound POST transferring that archive to an external cloud storage endpoint represents the Exfiltration tactic — moving stolen data out of the network. Command and Control refers to the communication channel itself, not the act of removing data.

Why the other options are wrong

  • B. Impact involves destructive or disruptive actions like data destruction, not data theft.
  • C. Collection (creating the RAR archive) already occurred in the prior command; the log shown is the transfer, not the gathering step.
  • D. C2 describes the attacker's control channel, not the data transfer of stolen files.

MITRE ATT&CK: Exfiltration

The Exfiltration tactic covers techniques attackers use to steal data from a network, often via C2 channels, cloud storage, or physical media.

  • Follows Collection in typical attack flow
  • Includes techniques like Exfiltration Over Web Service
  • Large or anomalous outbound transfers are key indicators

Memory trick: Collect the loot, Control the line, then Exfiltrate it out, finally cause Impact

More Vulnerability Management questions