An analyst reviews a mobile phishing alert: a user tapped a link to a fake company portal, then a prompt installed a malicious device configuration profile that enabled remote access. In MITRE ATT&CK, which tactic best describes the user action that first compromised the mobile device?
Select an answer to reveal the explanation.
Short Explanation
Think of a phishing link like your front door: once someone lets the attacker in, the door is already opened. The malicious profile may help stay inside, but the first compromise is still Initial Access. Don’t confuse what keeps the attacker in with how they got in.
Full Explanation
MITRE ATT&CK organizes attacker behavior by tactic, and a tactic answers the adversary’s objective rather than naming a specific command. In a mobile phishing scenario, the link and profile prompt are used to obtain the first foothold on the device, so the best tactic is Initial Access. A malicious profile may also support persistence, but the question asks for the framework stage that best fits the initial compromise, not the mechanism that keeps the attacker in place. The Execution concept is wrong because it describes running code or launching a payload after access exists, rather than the first foothold objective. The Defense Evasion concept is wrong because it covers bypassing controls, hiding artifacts, or avoiding detection, not the act of gaining entry. The Collection concept is wrong because it concerns gathering data from the device after the adversary already has a presence. Exam caveat: read whether the item asks for the first compromise, the maintaining mechanism, or a later data objective. Operational check: when triaging mobile phishing, tag the click or profile installation that creates the foothold as Initial Access, then separately evaluate the profile for persistence or exfiltration.