Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security operations center (SOC) analyst observes a series of suspicious events originating from an internal server. The server, which should only be communicating internally, is attempting to establish outbound connections to various unusual IP addresses on TCP port 22. The analyst suspects unauthorized remote access attempts or data exfiltration. Which common network port is being observed and what is its primary legitimate use?
- APort 21 (FTP) - File transfer
- BPort 80 (HTTP) - Web traffic
- CPort 22 (SSH) - Secure remote access
- DPort 23 (Telnet) - Unsecure remote access
Show answer & explanationAnswer & explanation
Correct answer: C. Port 22 (SSH) - Secure remote access
TCP port 22 is primarily used by SSH (Secure Shell), which provides secure remote access, command-line interface, remote command execution, and secure file transfer. Outbound connections on this port from an internal server that shouldn't be communicating externally are highly suspicious.
Why the other options are wrong
- A. Port 21 is for FTP, not secure remote access, and is less likely for C2.
- B. Port 80 is for HTTP web traffic, not typically for server-to-server C2 or remote access in this context.
- D. Port 23 is for Telnet, which is unsecure and rarely used legitimately today.
SSH (Secure Shell) Port 22
SSH is a cryptographic network protocol for operating network services securely over an unsecured network. Its default port is TCP 22. Common uses include remote command-line login, remote command execution, and secure file transfers (SFTP).
- Provides strong encryption and authentication.
- Replaced insecure protocols like Telnet and rlogin.
- Often targeted by attackers for unauthorized remote access.
Memory trick: SSH is like a 'secure shore' for your remote connections, always on port 22.