CompTIA SecurityX (CAS-005)Security OperationsHard

A security analyst is investigating a suspected data exfiltration incident. They have identified a compromised internal server that was observed making frequent, small outbound HTTP POST requests to an external IP address that changes periodically. The HTTP user-agent string used in these requests is highly unusual and inconsistent with any legitimate application on the server. What technique is the attacker most likely employing?

  1. AData Exfiltration via HTTP C2
  2. BCredential Stuffing
  3. CPort Scanning
  4. DWeb Shell
Show answer & explanation

Correct answer: A. Data Exfiltration via HTTP C2

The scenario describes a compromised server making frequent, small, outbound HTTP POST requests to a changing external IP with an unusual user-agent. This is characteristic of a command and control (C2) channel over HTTP, where data is exfiltrated in the POST request body or as part of the C2 communication, often disguised by unusual user-agents and dynamic IPs to evade detection.

Why the other options are wrong

  • B. Credential stuffing involves using stolen credentials to gain unauthorized access to accounts, which does not directly manifest as frequent outbound HTTP POST requests.
  • C. Port scanning involves scanning for open ports on target systems, not frequent outbound HTTP POST requests from a compromised server.
  • D. A web shell provides remote access to a compromised web server, but the observed behavior (frequent outbound POSTs to external, changing IPs) is more indicative of data exfiltration via a C2 channel rather than direct interactive web shell usage.

HTTP C2 for Data Exfiltration

A technique where attackers use HTTP/HTTPS for command and control (C2) communication and to exfiltrate data from a compromised system, often disguised as legitimate web traffic.

  • Leverages common web ports (80, 443) to evade detection.
  • Often uses HTTP GET for commands, HTTP POST for data exfiltration.
  • May employ unusual User-Agent strings, dynamic IPs/domains, or encrypted payloads.
  • Difficult to distinguish from legitimate web traffic without deep packet inspection.

Memory trick: Look for the ghost in the machine, whispering secrets through normal channels.

More Security Operations questions