CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

During incident triage, an analyst finds the following sequence of commands executed on a compromised Windows host: `wevtutil cl Security` `wevtutil cl System` `powershell.exe -Command "Set-MpPreference -DisableRealtimeMonitoring $true"` Which MITRE ATT&CK tactic do these actions represent?

  1. ACommand and Control
  2. BDefense Evasion
  3. CCollection
  4. DReconnaissance
Show answer & explanation

Correct answer: B. Defense Evasion

Clearing Windows Security and System event logs and disabling Windows Defender real-time monitoring are techniques used to avoid detection and remove forensic evidence, both of which fall under the Defense Evasion tactic in the MITRE ATT&CK framework.

Why the other options are wrong

  • A. Command and Control refers to communication channels with attacker infrastructure, not log clearing.
  • C. Collection refers to gathering data of interest from the target, not hiding activity.
  • D. Reconnaissance involves gathering information before or during an intrusion, not evading defenses on a compromised host.

MITRE ATT&CK: Defense Evasion

A tactic covering techniques adversaries use to avoid detection throughout an intrusion, such as clearing logs, disabling security tools, or masquerading files.

  • Includes Indicator Removal on Host (clearing event logs)
  • Includes Impair Defenses (disabling AV/EDR)
  • One of the largest tactic categories in ATT&CK Enterprise

Memory trick: Wiping logs and killing AV = sweeping footprints, Defense Evasion.

More Vulnerability Management questions