Quiz 5 Question 6 of 20

A Microsoft Sentinel incident involves a threat actor performing model extraction by repeatedly querying an Azure OpenAI deployment with carefully crafted inputs to reconstruct the model's behavior. The security team wants to map this attack to the MITRE ATT&CK framework. Which MITRE ATT&CK for Enterprise tactic best describes model extraction?

Select an answer to reveal the explanation.

Motivation