An analyst is evaluating a compromised system and observes behavior consistent with an adversary attempting to maintain persistent access to a network resource. According to the MITRE ATT&CK framework, which tactic BEST describes this behavior?
The correct answer is 'Persistence', which is a tactic in the MITRE ATT&CK framework that describes an adversary's goal to maintain their foothold within an environment. Persistence involves various techniques that adversaries can use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. 'Privilege Escalation' involves gaining higher-level permissions on a system or network but does not directly relate to maintaining access over time. 'Defense Evasion' involves avoiding detection, which is different from the act of maintaining access. 'Exfiltration' pertains to the act of stealing data, which is not the behavior in question regarding maintaining persistent access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the MITRE ATT&CK framework?
Open an interactive chat with Bash
What techniques might an adversary use to achieve Persistence?
Open an interactive chat with Bash
How does Persistence differ from other tactics like Privilege Escalation?