Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy

A security analyst is investigating a series of alerts indicating that multiple internal hosts are attempting to connect to an external IP address on port 443, but the traffic does not appear to be legitimate HTTPS. Further analysis reveals that the communication pattern is unusual and inconsistent with normal web browsing. Which common attack vector is most likely being utilized in this scenario?

  1. ASQL Injection
  2. BCommand and Control (C2)
  3. CPhishing
  4. DDistributed Denial of Service (DDoS)
Show answer & explanation

Correct answer: B. Command and Control (C2)

The scenario describes internal hosts attempting to communicate with an external IP address using a non-standard pattern over a common port, which is characteristic of Command and Control (C2) communication used by malware to receive instructions.

Why the other options are wrong

  • A. SQL injection targets databases through web application input, not external communication on port 443.
  • C. Phishing is a social engineering technique to trick users into revealing information, not a direct network communication attack vector like C2.
  • D. DDoS attacks aim to overwhelm a target with traffic, which doesn't align with internal hosts initiating unusual outbound connections.

Command and Control (C2)

Command and Control (C2) refers to the communication channel used by attackers to remotely control compromised systems (bots or zombies) within a network.

  • Enables attackers to issue commands and exfiltrate data.
  • Often uses common ports (e.g., 80, 443, 53) to blend with legitimate traffic.
  • Can employ various protocols, including HTTP, HTTPS, DNS, or custom protocols.

Memory trick: Malware Calls Out to its Commander.

More Security Concepts questions