Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is reviewing a SIEM dashboard and notices a sudden, significant increase in firewall 'deny' events for outbound traffic to a wide range of external IP addresses, all destined for TCP port 80 and 443. This activity originates from a single internal subnet that typically has minimal outbound web traffic. What is the most likely cause of this alert pattern?

  1. AMalware on the subnet is attempting to establish C2 communication or exfiltrate data.
  2. BAn internal user is attempting to bypass web filters.
  3. CA new legitimate application deployment is being blocked.
  4. DA phishing campaign is targeting internal users.
Show answer & explanation

Correct answer: A. Malware on the subnet is attempting to establish C2 communication or exfiltrate data.

A sudden surge of blocked outbound connections to various external IPs on common web ports from an unusual internal subnet strongly suggests malware attempting to communicate with command-and-control (C2) servers or exfiltrate data, which would often use common ports to blend in.

Why the other options are wrong

  • B. An individual user attempting to bypass web filters might generate some denies, but a 'significant increase' from an entire 'subnet' suggests automated, widespread activity, not a single user.
  • C. A new legitimate application would likely have a more predictable pattern of connections and would typically be identified and whitelisted, not result in widespread denies to many IPs.
  • D. A phishing campaign targets internal users, but the 'deny' events are for outbound traffic from a subnet, not inbound emails or user clicks causing outbound connections on *their* machines.

Command and Control (C2) Traffic

Communication between compromised systems (bots) and an attacker's C2 server, used for issuing commands, receiving updates, and exfiltrating data.

  • Often uses common ports (80, 443, 53) to blend with legitimate traffic.
  • Can be detected by unusual volume, destination patterns, or protocol anomalies.
  • A key indicator of an active compromise.

Memory trick: When traffic acts strange, danger's in range!

More Security Monitoring questions