Quiz 9 Question 14 of 20

A Windows system has been compromised. An attacker added a registry value under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options for 'sethc.exe' pointing to cmd.exe. What persistence and access technique does this implement?

Select an answer to reveal the explanation.

Motivation