Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard

A security operations center (SOC) analyst observes a series of suspicious events originating from an internal server: multiple failed login attempts to an external SSH server, followed by a successful connection, and then a large outbound data transfer to an unknown IP address. The analyst suspects command and control (C2) communication. Which port is most commonly associated with SSH, and thus a strong indicator in this C2 scenario?

  1. APort 23
  2. BPort 22
  3. CPort 21
  4. DPort 80
Show answer & explanation

Correct answer: B. Port 22

SSH (Secure Shell) typically operates on TCP port 22. In a C2 scenario, attackers often use SSH for encrypted communication and remote control of compromised systems, making traffic on port 22 to an external unknown IP highly suspicious, especially after failed logins.

Why the other options are wrong

  • A. Port 23 is for Telnet, an unencrypted protocol, not SSH.
  • C. Port 21 is for FTP (File Transfer Protocol), not SSH.
  • D. Port 80 is for HTTP (Hypertext Transfer Protocol), not SSH.

SSH (Secure Shell)

A cryptographic network protocol for operating network services securely over an unsecured network. It is typically used for remote command-line login and remote command execution, but also supports tunneling, port forwarding, and file transfers.

  • Uses TCP port 22 by default.
  • Provides strong authentication and encrypted communication.
  • Commonly used for remote administration.
  • Frequently abused by attackers for C2 channels or data exfiltration due to its encrypted nature.

Memory trick: Ports are digital doors; knowing their numbers helps identify what's coming and going.

More Security Concepts questions