A CS0-004 analyst sees an account use valid credentials to access ADMIN$ on a file server, then a service named SysUpdate is created and started on that server. Which event is best classified as persistence rather than lateral movement in an ATT&CK timeline?
Select an answer to reveal the explanation.
Short Explanation
Think of lateral movement as knocking on the next door, while persistence is leaving a key under the mat. Here, the ADMIN$ hit moves the threat to the file server, but the new service is what keeps coming back. You want to separate the travel from the foothold when building the ATT&CK timeline.
Full Explanation
MITRE ATT&CK separates tactics by adversary objective. Lateral movement is the activity that lets an adversary move from one system to another, such as authenticating to a remote administrative share. Persistence is the activity that gives the adversary continued access after a reboot or session change; creating a Windows service on the target system is a classic persistence technique because the service can be configured to start automatically and run under a chosen account. In the scenario, the ADMIN$ access establishes remote reachability, while the SysUpdate service creation establishes the durable foothold. Authenticated access to the ADMIN$ share is lateral movement because it is the remote administrative channel used to reach the target. Execution of a legitimate binary after the service starts is execution, not persistence, because running code is only the act of doing something once, not the mechanism that ensures it runs again. Use of stolen credentials to authenticate to the server is credential access or lateral movement support, not persistence, because the credential itself does not create a durable startup mechanism. Exam caveat: Do not classify every remote action as persistence; ask whether the activity enables movement or ensures future access. Operational check: Review service creation events and service start type to confirm the account, binary path, and auto-start setting on the affected host.