A security analyst attempts to start a company's database server. When the server starts, the analyst receives an error message indicating the database server did not pass authentication. After reviewing and testing the system, the analyst receives confirmation that the server has been compromised and that attackers have redirected all outgoing database traffic to a server under their control. Which of the following MITRE ATT&CK techniques did the attacker most likely use to redirect database traffic?
Choose an answer
Tap an option to check your answer.
Correct answer: Valid accounts.
Why this is the answer
The correct answer is Valid accounts. The attacker likely compromised valid credentials to gain access to the database server. Once authenticated, they could reconfigure the server to redirect traffic. The error message "database server did not pass authentication" strongly suggests an issue with the server's credentials or its ability to authenticate properly, which would be a direct consequence of an attacker using or manipulating valid accounts. Browser extension is incorrect because it relates to client-side browser manipulation, not server-side traffic redirection. Process injection is incorrect as it involves injecting malicious code into a running process, which might be a step in an attack but doesn't directly explain the traffic redirection or the authentication failure. Escape to host is incorrect because it refers to breaking out of a container or virtualized environment to access the underlying host system, which is not indicated by the scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed