CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

During incident triage, an analyst finds the following command run from an already-compromised workstation: `C:\Windows\System32> psexec.exe \\FIN-SRV02 -u CORP\svc_backup -p ******** cmd.exe /c whoami` The command successfully authenticates to a second, previously unaffected server and runs a command remotely. Which MITRE ATT&CK tactic does this action represent?

  1. ACollection
  2. BInitial Access
  3. CCommand and Control
  4. DLateral Movement
Show answer & explanation

Correct answer: D. Lateral Movement

Using PsExec with stolen credentials to remotely execute commands on another internal server is a classic Lateral Movement technique (T1021.002, Remote Services: SMB/Windows Admin Shares), allowing the adversary to pivot from the initially compromised workstation to additional systems within the network.

Why the other options are wrong

  • A. Collection involves gathering data of interest, not moving between systems.
  • B. Initial Access refers to the first foothold gained in the environment, which already occurred on the workstation.
  • C. Command and Control refers to communication with external attacker infrastructure, not internal pivoting.

MITRE ATT&CK: Lateral Movement

A tactic covering techniques adversaries use to move through a network from an initial foothold to additional systems, often using legitimate administrative tools and stolen credentials, such as PsExec, WMI, or RDP.

  • T1021.002: Remote Services (SMB/Windows Admin Shares) commonly implemented via PsExec
  • Relies on valid or stolen credentials to blend in with normal admin activity
  • Detected via monitoring unusual admin-share/service creation across hosts

Memory trick: PsExec is the attacker's stolen master key, unlocking one office door after another.

More Vulnerability Management questions