Quiz 10 Question 20 of 20

A SOC analyst reviews EDR telemetry showing a newly created scheduled task that launches a PowerShell script at system startup and runs as SYSTEM. The script was added after a user opened a malicious document. Which ATT&CK tactic does this behavior most directly represent?

Select an answer to reveal the explanation.

Motivation