CompTIA CySA+ (CS0-003)Vulnerability ManagementHard
During incident triage, an analyst finds the following sequence of commands executed on a compromised Windows host: `wevtutil cl Security` `wevtutil cl System` `powershell.exe -Command "Set-MpPreference -DisableRealtimeMonitoring $true"` Which MITRE ATT&CK tactic do these actions represent?
- ACommand and Control
- BDefense Evasion
- CCollection
- DReconnaissance
Show answer & explanationAnswer & explanation
Correct answer: B. Defense Evasion
Clearing Windows Security and System event logs and disabling Windows Defender real-time monitoring are techniques used to avoid detection and remove forensic evidence, both of which fall under the Defense Evasion tactic in the MITRE ATT&CK framework.
Why the other options are wrong
- A. Command and Control refers to communication channels with attacker infrastructure, not log clearing.
- C. Collection refers to gathering data of interest from the target, not hiding activity.
- D. Reconnaissance involves gathering information before or during an intrusion, not evading defenses on a compromised host.
MITRE ATT&CK: Defense Evasion
A tactic covering techniques adversaries use to avoid detection throughout an intrusion, such as clearing logs, disabling security tools, or masquerading files.
- Includes Indicator Removal on Host (clearing event logs)
- Includes Impair Defenses (disabling AV/EDR)
- One of the largest tactic categories in ATT&CK Enterprise
Memory trick: Wiping logs and killing AV = sweeping footprints, Defense Evasion.