Which MITRE ATT&CK Technique Redirected Database Traffic?

A security analyst attempts to start a company's database server. When the server starts, the analyst receives an error message indicating the database server did not pass authentication. After reviewing and testing the system, the analyst receives confirmation that the server has been compromised and that attackers have redirected all outgoing database traffic to a server under their control. Which of the following MITRE ATT&CK techniques did the attacker most likely use to redirect database traffic?

  1. Browser extension
  2. Process injection
  3. Valid accounts Source Reference Answer
  4. Escape to host

Community Votes

C
38%
D
35%
B
27%

38% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question traps test-takers into selecting a runtime exploitation method for traffic redirection, ignoring that altering server configurations fundamentally depends on prior credential compromise.

This question evaluates understanding of MITRE ATT&CK techniques used to gain and maintain system control, specifically highlighting how credential abuse enables configuration changes. The community consensus strongly favors Valid Accounts, recognizing that modifying network routing requires legitimate administrative privileges.

Candidates frequently select Process Injection or Escape to Host, incorrectly assuming these techniques directly manipulate network packets or container environments, rather than realizing that changing DNS, firewall rules, or proxy settings requires pre-existing valid credentials.

Community Discussion (18 comments)

jbmac 👍 5 Selected: C
The correct answer is: C. Valid accounts Explanation: The MITRE ATT&CK technique "Valid accounts" refers to the use of legitimate credentials (whether obtained through phishing, brute force, or other means) to gain unauthorized access to systems and services. In this case, the attacker likely leveraged valid credentials to compromise the database server and redirect outgoing traffic to a server they control. This technique involves using accounts that are already authorized to bypass security mechanisms and perform malicious actions without raising alarms.
jacobtriestech 👍 5 Selected: D
Escape to host is a technique where an attacker gains unauthorized access to a system and then pivots to other systems within the network. In this case, the attacker gained access to the database server and then redirected its traffic to a controlled server. This indicates a successful escape to host.
lukascorpwork 👍 1 Selected: D
D. "Escape to host" is a privilege escalation or container breakout technique where an attacker, after compromising a virtualized or containerized system, gains control over the host machine. This would allow them to modify network settings, reroute traffic, and take control over database connections—exactly what happened in this case.
JoeRealCool 👍 1 Selected: C
It's valid accounts. The attacker used a valid account and changed the password, thus leading to the error message during authentication.
prabh1251 👍 1 Selected: C
Process Injection is a technique where attackers inject malicious code into legitimate processes, enabling them to intercept or redirect network traffic., what is Escape to Host? Escape to Host is a MITRE ATT&CK technique where: ✔️ An attacker breaks out of a sandboxed or virtualized environment (like a container or VM). ✔️ The goal is to gain control of the host machine — not just redirect traffic or compromise a service.
itsgonnabemay 👍 1 Selected: D
"Valid Accounts" refers to an adversary leveraging legitimate credentials, while "Escape to Host" (or container escape) involves an adversary moving from a container to the host machine to gain broader access
prabh1251 👍 2 Selected: B
Process injection is a technique where an attacker inserts malicious code into a legitimate process, which allows them to: ✅ Gain higher privileges. ✅ Manipulate the process’s behavior. ✅ Redirect traffic or steal data without detection. In this case: The attacker likely injected code into the database server process. This allowed them to redirect database traffic to a malicious server.
VincentvdS 👍 2 Selected: B
Nice.. ChatGPT says B, CoPilot says C, Community says D.. Its nice if you add the answer of chatgpt in Copilot.. lol..
9149f41 👍 2 Selected: B
Valid Accounts explains how the attacker gained access to the server. Process Injection explains how the attacker redirected traffic after gaining access. Both techniques are part of the attack chain, but Process Injection is the most relevant to the traffic redirection described in the scenario. Without Process Injection (or a similar technique), the attacker could not have redirected the traffic, even with valid credentials.
93bdd7c 👍 1 Selected: C
The attacker most likely used the Valid Accounts technique to redirect database traffic. This technique involves an attacker obtaining and using legitimate credentials to bypass authentication and gain access to systems, servers, or services. In this scenario, the error message suggests authentication failure, implying that attackers used valid credentials to reconfigure the server or its network settings, and then set up traffic redirection to exfiltrate data or reroute traffic to a malicious server under their control. Another possible technique that could have been used is Process Injection, which involves injecting malicious code into legitimate processes. This technique can be used to intercept and redirect database traffic to a server under the attacker’s control. However, based on the information provided, Valid Accounts is the most likely technique used by the attacker.
pindinga1 👍 1 Selected: C
The correct answer is C. Valid accounts. Valid accounts is a technique in the MITRE ATT&CK framework where attackers use stolen or compromised legitimate credentials to gain access to a system. In this case, the attackers likely used valid accounts to redirect outgoing database traffic to a server under their control, as they would have had the necessary privileges to modify the database configurations or intercept traffic without triggering alarms.
laternak26 👍 4 Selected: B
Process injection is a technique where an attacker injects malicious code into a legitimate process to evade detection or alter the behavior of that process. In this case, the attackers could have injected code into a legitimate database process to redirect the database traffic. NOT C. Valid accounts because it is not even MITRE Technique. D. Espace to host means escaping from VM to Host not redirecting network traffic.
ProudFather 👍 4 Selected: D
An escape to host attack allows an attacker to break out of a sandboxed environment, such as a virtual machine or container, and gain access to the underlying host system. In this case, the attacker likely exploited a vulnerability in the database server's software or configuration to escape its security constraints and redirect network traffic.
Exam_Prep221 👍 2 Selected: C
Why not the others? A. Browser extension: This technique is used to manipulate or spy on browser-based activity. It does not apply to redirecting database traffic or compromising a database server. B. Process injection: This technique involves injecting malicious code into legitimate processes. While it can evade detection or escalate privileges, it does not directly explain how traffic was redirected. D. Escape to host: This technique applies to virtualized environments (e.g., escaping from a guest VM to the host system) and is unrelated to database traffic redirection.
Exam_Prep221 👍 1 Selected: C
The attackers were able to redirect outgoing database traffic to a server they control, which strongly indicates that they had legitimate credentials or valid accounts to access and manipulate the database server or network configurations. The Valid Accounts technique (T1078 in MITRE ATT&CK) involves an attacker obtaining and using legitimate credentials to bypass authentication and gain access to systems, servers, or services. In this scenario: The error message suggests authentication failure, implying that attackers used valid credentials to reconfigure the server or its network settings. They likely set up traffic redirection (e.g., via configuration changes or tunneling) to exfiltrate data or reroute traffic to a malicious server under their control.
cda26aa 👍 4
The MITRE ATT&CK technique most likely used by the attacker to redirect database traffic is B. Process injection. Here's why: Process injection involves injecting malicious code into a legitimate process, allowing the attacker to manipulate the process and redirect traffic without being detected by the operating system2. This technique can be used to intercept and redirect database traffic to a server under the attacker's control. Other options like browser extension, valid accounts, and escape to host are less likely to be directly involved in redirecting database traffic in this scenario.
srtysrhtyjumnuyedt 👍 2 Selected: D
D is correct. According to the MITRE ATT&CK framework: "Escape to Host Adversaries may break out of a container to gain access to the underlying host. This can allow an adversary access to other containerized resources from the host level or to the host itself. In principle, containerized resources should provide a clear separation of application functionality and be isolated from the host environment. [...] Gaining access to the host may provide the adversary with the opportunity to achieve follow-on objectives, such as establishing persistence, moving laterally within the environment, accessing other containers running on the host, or setting up a command and control channel on the host."
b82faaf 👍 2 Selected: C
Valid accounts is a MITRE ATT&CK technique used in this case.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Scenario Breakdown

The scenario describes a compromised database server where outgoing traffic has been rerouted. While the visible outcome is traffic redirection, the question asks for the underlying MITRE ATT&CK technique that enabled this state change.

Why Valid Accounts is Correct

In the MITRE ATT&CK framework, Valid Accounts (T1078) refers to adversaries obtaining and using legitimate credentials to bypass authentication and gain authorized access. As noted in community discussions, the initial authentication failure suggests attackers altered credentials or leveraged stolen ones to modify system configurations (such as DNS resolvers, proxy settings, or database connection strings). Without valid administrative privileges, an attacker cannot persistently redirect outbound traffic at the OS or application level. Community user [4] correctly highlights that the authentication error points directly to credential manipulation, making Valid Accounts the foundational enabler.

Why Other Options Are Incorrect

  • Browser Extension (A) is designed to manipulate client-side web browsing activity and has no relevance to backend database server routing or infrastructure compromise.
  • Process Injection (B) involves injecting malicious code into a running process to evade detection or escalate privileges. While technically capable of intercepting data in memory, it does not inherently explain persistent network traffic redirection or configuration modification. As community member [9] points out, while injection might be part of an attack chain, it doesn't account for the configuration-level changes required here.
  • Escape to Host (D) describes a container or VM breakout technique to reach the underlying hypervisor/host OS. The scenario provides no evidence of virtualization boundaries being breached, making this a distractor based on terminology confusion. Community user [6] clarifies that escape techniques focus on environment boundaries, not traffic routing.
Ultimately, certification exams often test the prerequisite condition for persistence and control. Credential abuse is the foundational enabler that allows subsequent technical manipulations like traffic redirection.

Official Reference

Exam Strategy

When answering MITRE ATT&CK questions, distinguish between the enabler (how access was gained) and the execution method (how the action was performed). If the scenario highlights configuration changes, persistent access, or authentication anomalies, prioritize credential-based techniques over runtime exploitation methods unless explicit memory or container details are provided.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide