CompTIA Security+ (SY0-701)Security OperationsHard
During an active incident, a forensic analyst reviews NetFlow data and notices a workstation communicating with an unusual external IP over port 4444 shortly before a spike in outbound traffic to multiple internal hosts. Which activity does this pattern most likely indicate?
- ALateral movement following initial compromise
- BNormal DNS resolution traffic
- CScheduled patch management traffic
- DLegitimate VPN tunnel establishment
Show answer & explanationAnswer & explanation
Correct answer: A. Lateral movement following initial compromise
Communication with an external IP over a non-standard, commonly exploited port (4444 is a well-known default for Metasploit reverse shells) followed by increased internal outbound connections is a classic indicator of a compromised host pivoting to spread laterally within the network.
Why the other options are wrong
- B. DNS traffic uses port 53 and does not match this pattern.
- C. Patch management traffic typically uses standard update ports and internal management servers, not external unusual IPs.
- D. VPN traffic uses recognized ports like 443 or 1194 and does not typically precede internal spread patterns.
Lateral Movement Indicators
Network behavior patterns, such as unusual ports and internal connection spikes following external C2 communication, that suggest an attacker is spreading through a network.
- Port 4444 is a common default for Metasploit reverse shells
- NetFlow analysis helps identify anomalous traffic patterns
- Spike in internal connections after external contact suggests pivoting
Memory trick: Port 4444 knocking, then spreading like a spider.