Phishing belongstowhich of the following MITRE ATT&CK tactics?
A.
Initial Access, Persistence
B.
Persistence, Command and Control
C.
Reconnaissance, Persistence
D.
Reconnaissance, Initial Access
The Answer Is:
D
This question includes an explanation.
Explanation:
Phishing is a technique that belongs to two MITRE ATT&CK tactics: Reconnaissance and Initial Access. Reconnaissance is the process of gathering information about a target before launching an attack. Phishing for information is a sub-technique of Reconnaissance that involves sending phishing messages to elicit sensitive information that can be used during targeting. Initial Access is the process of gaining a foothold in a network or system. Phishing is a sub-technique of Initial Access that involves sending phishing messages to execute malicious code on victim systems. Phishing can be used for both Reconnaissance and Initial Access depending on the objective and content of the phishing message. References: