CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A SOC analyst reviewing endpoint logs finds the following command executed on a workstation: `powershell.exe -NoP -NonI -W Hidden -Enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkA...` Using the MITRE ATT&CK framework, this activity most directly maps to which tactic?

  1. AReconnaissance
  2. BPersistence
  3. CExfiltration
  4. DExecution
Show answer & explanation

Correct answer: D. Execution

Running an encoded PowerShell command to execute code (here decoding to download and run further payloads) falls under the ATT&CK Execution tactic (e.g., T1059.001 PowerShell), which covers techniques that run adversary-controlled code on a system.

Why the other options are wrong

  • A. Reconnaissance covers information gathering before compromise, not code execution.
  • B. Persistence covers maintaining access (e.g., scheduled tasks), not the act of running the command itself.
  • C. Exfiltration refers to moving stolen data out, which is not shown here.

MITRE ATT&CK Execution Tactic

Techniques adversaries use to run malicious code on a local or remote system, such as PowerShell, scripting, or command-line interpreters.

  • T1059 covers command and scripting interpreters
  • Encoded/obfuscated PowerShell is a common evasion technique
  • Execution often precedes persistence and lateral movement

Memory trick: Encoded PowerShell = the attacker's remote control button being pressed.

More Vulnerability Management questions