Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CS0-004 Exam - Topic 4 Question 6 Discussion

A security analyst responds to an alert regarding identity and access management activity within the cloud environment. The attacker is currently trying to gain access from one isolated cloud subscription to another via a compromised user role.Which of the following aspects of the MITRE ATT&CK framework is the attacker trying to perform?
B) Lateral movement
A) Privilege escalation
C) Persistence
D) Execution
E) Credential access

CompTIA CS0-004 Exam - Topic 4 Question 6 Discussion

Actual exam question for CompTIA's CS0-004 exam
Question #: 6
Topic #: 4
[All CS0-004 Questions]

A security analyst responds to an alert regarding identity and access management activity within the cloud environment. The attacker is currently trying to gain access from one isolated cloud subscription to another via a compromised user role.

Which of the following aspects of the MITRE ATT&CK framework is the attacker trying to perform?

Show Suggested Answer Hide Answer
Suggested Answer: B

The attacker is attempting lateral movement because an already compromised identity is being used to move from one cloud environment or subscription into another. Lateral movement describes adversary activity intended to reach additional systems, services, accounts, or resources after an initial foothold has been established.

MITRE ATT&CK specifically includes cloud-oriented lateral movement. Its Lateral Movement tactic documents adversaries using valid accounts to access additional cloud services and resources within compromised environments. MITRE also documents cloud-role manipulation that may enable movement into additional accounts, demonstrating how identity and role relationships can become lateral-movement pathways in cloud architectures.

Privilege escalation would apply if the attacker were primarily attempting to obtain greater permissions within the current security context. Persistence concerns maintaining long-term access. Execution concerns running malicious code or commands. Credential access involves obtaining credentials or authentication material.

In this scenario, the attacker already possesses a compromised user role. The objective is to use that existing access to traverse a trust boundary and reach another isolated subscription. That movement between security domains is the decisive indicator of the Lateral Movement tactic.

Study Guide Reference: Security Operations MITRE ATT&CK Lateral Movement Cloud Services Valid Accounts IAM Roles Cross-Subscription Access.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel