Q63
Single choice
A media streaming company in Los Angeles, California engages a certified ethical hacker to evaluate the resilience of its cloud-hosted infrastructure. After initial access is obtained through an exposed credential in a development repository, the tester systematically modifies logging configurations, establishes alternate access keys for persistence, and documents privilege relationships between services within the tenant.
The tester's actions are focused on maintaining continued access and mapping the internal structure of the environment after initial compromise has occurred.
Within the cloud attack lifecycle, which phase best represents this stage of activity?