Quiz 11 Question 2 of 20

During triage, an EDR alert shows a suspicious process enumerating user documents, overwriting them with encrypted contents, renaming files with a new extension, and dropping a ransom note in each folder. The same process did not exploit a service, add a scheduled task, or disable logging. Which MITRE ATT&CK tactic best describes this observed behavior?

Select an answer to reveal the explanation.

Motivation