Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringHard
A security analyst is investigating a series of alerts indicating unusual outbound network connections from several internal workstations to an external IP address known for hosting C2 (Command and Control) infrastructure. The connections are occurring over TCP port 443, but the traffic does not appear to be legitimate HTTPS. What technique is the attacker most likely employing?
- ASMB Relay Attack
- BProtocol Mismatching
- CDNS Tunneling
- DICMP Exfiltration
Show answer & explanationAnswer & explanation
Correct answer: B. Protocol Mismatching
Protocol mismatching, also known as protocol evasion or port masquerading, involves using a standard port (like 443 for HTTPS) for non-standard or malicious traffic to bypass firewall rules that typically allow outbound traffic on common ports. The key indicator is that traffic on port 443 'does not appear to be legitimate HTTPS'.
Why the other options are wrong
- A. SMB relay attacks target NTLM authentication and are typically internal, not outbound C2 over TCP 443 with protocol anomalies.
- C. DNS tunneling uses DNS queries/responses to tunnel data, not typically TCP 443 for C2.
- D. ICMP exfiltration uses ICMP packets to transfer data, which is a different protocol and port usage than described.
Protocol Mismatching/Port Masquerading
A technique where attackers use a well-known port (e.g., 80, 443) for a protocol other than its standard, often to bypass firewall rules and network monitoring.
- Leverages trust in common ports to hide malicious traffic.
- Requires deep packet inspection (DPI) to detect.
- Often used for C2 communication or data exfiltration.
Memory trick: Attackers hide in plain sight, changing their clothes to look alright!