CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A SOC analyst reviewing endpoint logs finds the following command executed on a workstation: `powershell.exe -NoP -NonI -W Hidden -Enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkA...` Using the MITRE ATT&CK framework, this activity most directly maps to which tactic?
- AReconnaissance
- BPersistence
- CExfiltration
- DExecution
Show answer & explanationAnswer & explanation
Correct answer: D. Execution
Running an encoded PowerShell command to execute code (here decoding to download and run further payloads) falls under the ATT&CK Execution tactic (e.g., T1059.001 PowerShell), which covers techniques that run adversary-controlled code on a system.
Why the other options are wrong
- A. Reconnaissance covers information gathering before compromise, not code execution.
- B. Persistence covers maintaining access (e.g., scheduled tasks), not the act of running the command itself.
- C. Exfiltration refers to moving stolen data out, which is not shown here.
MITRE ATT&CK Execution Tactic
Techniques adversaries use to run malicious code on a local or remote system, such as PowerShell, scripting, or command-line interpreters.
- T1059 covers command and scripting interpreters
- Encoded/obfuscated PowerShell is a common evasion technique
- Execution often precedes persistence and lateral movement
Memory trick: Encoded PowerShell = the attacker's remote control button being pressed.