Quiz 10 Question 3 of 20

An EDR alert shows a suspicious process opening lsass.exe with PROCESS_VM_READ rights and extracting authentication material. Which MITRE ATT&CK technique best maps this observed credential-access behavior?

Select an answer to reveal the explanation.

Motivation