CompTIA SecurityX (CAS-005)Security OperationsMedium

A security operations center (SOC) analyst observes a significant increase in network traffic originating from an internal server to various external IP addresses on non-standard ports. Further investigation reveals that the server is communicating with multiple seemingly unrelated domains and IP addresses in short, bursty intervals. The server's primary function is an internal database, and it should not be initiating external connections. Which of the following attack indicators is MOST likely being observed?

  1. ASQL injection attempts
  2. BDistributed Denial of Service (DDoS) attack launch
  3. CCommand and control (C2) communication
  4. DInternal port scanning
Show answer & explanation

Correct answer: C. Command and control (C2) communication

The observed pattern of bursty, non-standard port communication to multiple external, unrelated domains from an internal server whose primary function does not involve external connections is highly indicative of command and control (C2) activity. This behavior suggests a compromised system receiving instructions or exfiltrating data.

Why the other options are wrong

  • A. SQL injection attempts typically involve inbound requests to a database server, not outbound communication from it.
  • B. Launching a DDoS attack would typically involve a massive surge of outbound traffic to specific targets, often on standard ports, not bursty communication to unrelated domains.
  • D. Internal port scanning would involve outbound traffic to other internal hosts, not external IP addresses and domains.

Command and Control (C2)

Command and Control (C2 or C&C) refers to the communication channel used by an attacker to remotely control compromised systems (bots or zombies) within a target network.

  • Enables attackers to send commands and receive data from compromised machines.
  • Often uses covert channels, non-standard ports, or legitimate protocols (e.g., HTTP, DNS) to blend in.
  • Detection is crucial for identifying active compromises and preventing further damage.

Memory trick: Compromised servers Communicate Covertly.

More Security Operations questions