Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst is reviewing a SIEM dashboard and notices a sudden, significant increase in firewall 'deny' events for outbound traffic to a wide range of external IP addresses, all destined for TCP port 80 and 443. This activity originates from a single internal subnet that typically has minimal outbound web traffic. What is the most likely cause of this alert pattern?
- AMalware on the subnet is attempting to establish C2 communication or exfiltrate data.
- BAn internal user is attempting to bypass web filters.
- CA new legitimate application deployment is being blocked.
- DA phishing campaign is targeting internal users.
Show answer & explanationAnswer & explanation
Correct answer: A. Malware on the subnet is attempting to establish C2 communication or exfiltrate data.
A sudden surge of blocked outbound connections to various external IPs on common web ports from an unusual internal subnet strongly suggests malware attempting to communicate with command-and-control (C2) servers or exfiltrate data, which would often use common ports to blend in.
Why the other options are wrong
- B. An individual user attempting to bypass web filters might generate some denies, but a 'significant increase' from an entire 'subnet' suggests automated, widespread activity, not a single user.
- C. A new legitimate application would likely have a more predictable pattern of connections and would typically be identified and whitelisted, not result in widespread denies to many IPs.
- D. A phishing campaign targets internal users, but the 'deny' events are for outbound traffic from a subnet, not inbound emails or user clicks causing outbound connections on *their* machines.
Command and Control (C2) Traffic
Communication between compromised systems (bots) and an attacker's C2 server, used for issuing commands, receiving updates, and exfiltrating data.
- Often uses common ports (80, 443, 53) to blend with legitimate traffic.
- Can be detected by unusual volume, destination patterns, or protocol anomalies.
- A key indicator of an active compromise.
Memory trick: When traffic acts strange, danger's in range!