Q: 13
A systems administrator is reviewing after-hours traffic flows from data-center servers and sees
regular outgoing HTTPS connections from one of the servers to a public IP address. The server should
not be making outgoing connections after hours. Looking closer, the administrator sees this traffic
pattern around the clock during work hours as well. Which of the following is the most likely
explanation?
Options
Discussion
Yeah, looks like A to me.
Maybe A. Outbound HTTPS at regular intervals really sounds like C2 beaconing, especially if it's ongoing outside business hours. Can't be sure it's not exfiltration but the pattern fits command and control more. Anyone disagree?
Don’t think it’s B, since exfiltration tends to show larger or sporadic data bursts. Regular outbound HTTPS at odd hours is textbook C2 beaconing activity (A). Trap is C, but here the port isn’t unusual.
Ugh, one of those "most likely" phrasing questions again. Probably A, but what if the keyword was "best remediation"-would that change things?
Be respectful. No spam.