CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security engineer is tasked with implementing server hardening best practices across a fleet of Linux servers. The organization requires a method to quickly identify all open ports and established connections on a given server to detect unauthorized services or suspicious communication. Which command-line utility is MOST appropriate for this task?
- Aifconfig
- Bnetstat
- Ctraceroute
- Dping
Show answer & explanationAnswer & explanation
Correct answer: B. netstat
`netstat` (network statistics) is a command-line utility that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics. It is ideal for identifying open ports (listening services) and established connections to detect unauthorized activity.
Why the other options are wrong
- A. `ifconfig` (or `ip addr`) is used to configure or display network interface parameters, not to list open ports or established connections.
- C. `traceroute` displays the route and measures transit delays of packets across an IP network, not for listing open ports or connections.
- D. `ping` is used to test reachability of a host on an Internet Protocol (IP) network, not to list open ports or connections.
netstat
netstat is a command-line utility for displaying network connections (both incoming and outgoing), routing tables, and a number of network interface statistics.
- Identifies open ports and listening services.
- Shows active network connections.
- Useful for troubleshooting network issues and security auditing.
Memory trick: netstat sees all network stats, like a network detective.