Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security analyst is investigating a suspected malware infection on an internal host. The host is exhibiting unusual outbound connections to a known malicious IP address on TCP port 443, but the traffic does not appear to be encrypted with TLS/SSL as expected. Which type of intrusion is most likely occurring?
- ASQL Injection
- BDNS Tunneling
- CPort Misuse
- DICMP Tunneling
Show answer & explanationAnswer & explanation
Correct answer: C. Port Misuse
The scenario describes traffic on a standard port (443) that is not behaving as expected for that port's typical protocol (TLS/SSL). This indicates that a different, potentially malicious, protocol is using the port, which is characteristic of port misuse.
Why the other options are wrong
- A. SQL injection is an attack on databases, typically via web application inputs, not a network-level tunneling technique.
- B. DNS tunneling uses DNS queries/responses to exfiltrate data, not directly TCP port 443 with non-TLS traffic.
- D. ICMP tunneling uses ICMP packets to tunnel data, not TCP port 443.
Port Misuse
Port misuse occurs when an attacker uses a standard, often allowed, network port (e.g., 80, 443, 53) for non-standard or malicious communication to evade detection.
- Evades firewall rules that allow standard ports.
- Often used by malware for command and control (C2).
- Detection requires deep packet inspection or behavioral analysis.
Memory trick: Anomalies are like traffic light violations: something's not right on the usual route.