Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst is investigating a suspected malware infection on an internal host. The host is exhibiting unusual outbound connections to a known malicious IP address on TCP port 443, but the traffic does not appear to be encrypted with TLS/SSL as expected. Which type of intrusion is most likely occurring?

  1. ASQL Injection
  2. BDNS Tunneling
  3. CPort Misuse
  4. DICMP Tunneling
Show answer & explanation

Correct answer: C. Port Misuse

The scenario describes traffic on a standard port (443) that is not behaving as expected for that port's typical protocol (TLS/SSL). This indicates that a different, potentially malicious, protocol is using the port, which is characteristic of port misuse.

Why the other options are wrong

  • A. SQL injection is an attack on databases, typically via web application inputs, not a network-level tunneling technique.
  • B. DNS tunneling uses DNS queries/responses to exfiltrate data, not directly TCP port 443 with non-TLS traffic.
  • D. ICMP tunneling uses ICMP packets to tunnel data, not TCP port 443.

Port Misuse

Port misuse occurs when an attacker uses a standard, often allowed, network port (e.g., 80, 443, 53) for non-standard or malicious communication to evade detection.

  • Evades firewall rules that allow standard ports.
  • Often used by malware for command and control (C2).
  • Detection requires deep packet inspection or behavioral analysis.

Memory trick: Anomalies are like traffic light violations: something's not right on the usual route.

More Security Monitoring questions