CompTIA SecurityX (CAS-005)Security EngineeringEasy

A security engineer is tasked with implementing server hardening best practices across a fleet of Linux servers. The organization requires a method to quickly identify all open ports and established connections on a given server to detect unauthorized services or suspicious communication. Which command-line utility is MOST appropriate for this task?

  1. Aifconfig
  2. Bnetstat
  3. Ctraceroute
  4. Dping
Show answer & explanation

Correct answer: B. netstat

`netstat` (network statistics) is a command-line utility that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics. It is ideal for identifying open ports (listening services) and established connections to detect unauthorized activity.

Why the other options are wrong

  • A. `ifconfig` (or `ip addr`) is used to configure or display network interface parameters, not to list open ports or established connections.
  • C. `traceroute` displays the route and measures transit delays of packets across an IP network, not for listing open ports or connections.
  • D. `ping` is used to test reachability of a host on an Internet Protocol (IP) network, not to list open ports or connections.

netstat

netstat is a command-line utility for displaying network connections (both incoming and outgoing), routing tables, and a number of network interface statistics.

  • Identifies open ports and listening services.
  • Shows active network connections.
  • Useful for troubleshooting network issues and security auditing.

Memory trick: netstat sees all network stats, like a network detective.

More Security Engineering questions