Quiz 1 Question 15 of 20

During log correlation in a SIEM, an analyst notices: a firewall allows RDP from an external IP, followed 2 minutes later by a Windows Security log showing a successful logon for a service account, followed by execution of PowerShell with encoded commands. What attack phases does this sequence represent?

Select an answer to reveal the explanation.

Motivation