Which MITRE ATT&CK Technique Redirected Database Traffic?
A security analyst attempts to start a company's database server. When the server starts, the analyst receives an error message indicating the database server did not pass authentication. After reviewing and testing the system, the analyst receives confirmation that the server has been compromised and that attackers have redirected all outgoing database traffic to a server under their control. Which of the following MITRE ATT&CK techniques did the attacker most likely use to redirect database traffic?
Community Votes
38% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question traps test-takers into selecting a runtime exploitation method for traffic redirection, ignoring that altering server configurations fundamentally depends on prior credential compromise.
This question evaluates understanding of MITRE ATT&CK techniques used to gain and maintain system control, specifically highlighting how credential abuse enables configuration changes. The community consensus strongly favors Valid Accounts, recognizing that modifying network routing requires legitimate administrative privileges.
Candidates frequently select Process Injection or Escape to Host, incorrectly assuming these techniques directly manipulate network packets or container environments, rather than realizing that changing DNS, firewall rules, or proxy settings requires pre-existing valid credentials.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Scenario Breakdown
The scenario describes a compromised database server where outgoing traffic has been rerouted. While the visible outcome is traffic redirection, the question asks for the underlying MITRE ATT&CK technique that enabled this state change.Why Valid Accounts is Correct
In the MITRE ATT&CK framework, Valid Accounts (T1078) refers to adversaries obtaining and using legitimate credentials to bypass authentication and gain authorized access. As noted in community discussions, the initial authentication failure suggests attackers altered credentials or leveraged stolen ones to modify system configurations (such as DNS resolvers, proxy settings, or database connection strings). Without valid administrative privileges, an attacker cannot persistently redirect outbound traffic at the OS or application level. Community user [4] correctly highlights that the authentication error points directly to credential manipulation, making Valid Accounts the foundational enabler.Why Other Options Are Incorrect
- Browser Extension (A) is designed to manipulate client-side web browsing activity and has no relevance to backend database server routing or infrastructure compromise.
- Process Injection (B) involves injecting malicious code into a running process to evade detection or escalate privileges. While technically capable of intercepting data in memory, it does not inherently explain persistent network traffic redirection or configuration modification. As community member [9] points out, while injection might be part of an attack chain, it doesn't account for the configuration-level changes required here.
- Escape to Host (D) describes a container or VM breakout technique to reach the underlying hypervisor/host OS. The scenario provides no evidence of virtualization boundaries being breached, making this a distractor based on terminology confusion. Community user [6] clarifies that escape techniques focus on environment boundaries, not traffic routing.
Official Reference
Exam Strategy
When answering MITRE ATT&CK questions, distinguish between the enabler (how access was gained) and the execution method (how the action was performed). If the scenario highlights configuration changes, persistent access, or authentication anomalies, prioritize credential-based techniques over runtime exploitation methods unless explicit memory or container details are provided.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →