Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium
A network administrator notices unusual outbound traffic patterns originating from several internal workstations, including connections to unknown IP addresses on high-numbered ports. The traffic volume is low but persistent. Users report no issues with their applications. Which of the following best describes the most likely type of security threat occurring?
- AMalware infection (e.g., botnet activity)
- BSQL injection
- CDenial of Service (DoS) attack
- DPhishing attempt
Show answer & explanationAnswer & explanation
Correct answer: A. Malware infection (e.g., botnet activity)
Unusual outbound traffic to unknown IP addresses on high-numbered ports, especially when users report no issues, is a classic indicator of malware, often part of a botnet. The infected machines are likely communicating with a command-and-control server.
Why the other options are wrong
- B. SQL injection targets databases through web application vulnerabilities and would manifest as database errors or data manipulation, not generalized outbound network traffic from workstations.
- C. DoS attacks typically involve high volume inbound traffic aiming to overwhelm a target, not low volume outbound traffic from internal hosts.
- D. Phishing is a social engineering technique to trick users into revealing information, not a direct cause of unusual outbound network traffic from infected machines.
Malware Indicators
Signs that a system may be infected with malicious software, often including unusual network activity, performance degradation, or unexpected pop-ups.
- Unusual outbound network connections
- System performance issues without clear cause
- Unexpected pop-ups or browser redirects
- Modified system files or settings
Memory trick: Malware's 'M' for Mysterious Moves: Check the Network, Performance, and Pop-ups.