CompTIA CySA+ (CS0-003)Incident Response and ManagementHard

A security analyst is reviewing a firewall log from a critical server and observes the following entries: ``` TIME SRC_IP DST_IP DST_PORT PROTOCOL ACTION 2023-11-15 10:00:01 192.168.1.10 10.0.0.50 80 TCP ALLOW 2023-11-15 10:00:02 192.168.1.10 10.0.0.50 443 TCP ALLOW 2023-11-15 10:00:03 192.168.1.10 10.0.0.50 22 TCP DENY 2023-11-15 10:00:04 192.168.1.10 10.0.0.50 3389 TCP DENY 2023-11-15 10:00:05 192.168.1.10 10.0.0.50 53 UDP ALLOW 2023-11-15 10:00:06 192.168.1.10 10.0.0.50 53 TCP DENY 2023-11-15 10:00:07 192.168.1.10 10.0.0.50 135 TCP DENY 2023-11-15 10:00:08 192.168.1.10 10.0.0.50 137 UDP DENY 2023-11-15 10:00:09 192.168.1.10 10.0.0.50 138 UDP DENY 2023-11-15 10:00:10 192.168.1.10 10.0.0.50 139 TCP DENY 2023-11-15 10:00:11 192.168.1.10 10.0.0.50 445 TCP DENY ``` Which of the following attack types is the source IP `192.168.1.10` MOST likely attempting to conduct against `10.0.0.50`?

  1. ASMB/NetBIOS enumeration or exploitation
  2. BBrute-force SSH attack
  3. CWeb application attack (HTTP/HTTPS)
  4. DDNS exfiltration
Show answer & explanation

Correct answer: A. SMB/NetBIOS enumeration or exploitation

The repeated DENY actions on ports 135 (RPC), 137 (NetBIOS Name Service), 138 (NetBIOS Datagram Service), 139 (NetBIOS Session Service), and 445 (SMB over TCP) are strong indicators of an attempt to enumerate or exploit services related to Server Message Block (SMB) and NetBIOS, commonly used for Windows file sharing and directory services.

Why the other options are wrong

  • B. Port 22 (SSH) is denied, indicating an SSH attempt was made, but the significantly larger number of denied attempts on SMB/NetBIOS ports points to a different primary attack vector.
  • C. While ports 80 and 443 are allowed, the subsequent denied attempts on very specific Windows networking ports suggest a different, more targeted attack than a general web application attack.
  • D. Port 53 (DNS) is allowed for UDP, but there's no indication of high volume or suspicious queries that would suggest DNS exfiltration. The denied TCP port 53 is also not typical for exfiltration.

SMB/NetBIOS Attack Indicators

Network log patterns showing attempts to connect to or interact with ports associated with Server Message Block (SMB) and NetBIOS services.

  • Target ports: 135 (RPC), 137 (NetBIOS NS), 138 (NetBIOS DS), 139 (NetBIOS SS), 445 (SMB).
  • Often used for enumeration, credential dumping, or lateral movement.
  • Common in Windows environments.

Memory trick: Ports tell the story: 22 is SSH, 80/443 Web, and 139/445 are SMB.

More Incident Response and Management questions