Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A security analyst is investigating a compromised internal server that was accessed from an external IP address. The firewall logs show a connection originating from an IP address that is not part of the company's approved vendor list or remote access VPN pool. Which type of attack is most likely indicated by this activity?

  1. ASQL Injection
  2. BUnauthorized Access
  3. CBrute-Force Attack
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. Unauthorized Access

The scenario describes an external IP address connecting to an internal server without authorization, which is a clear indication of unauthorized access. While other attacks might follow, the initial unauthorized connection is the primary issue.

Why the other options are wrong

  • A. SQL Injection is an attack that targets databases through web application input, not direct server access from an unknown IP.
  • C. A brute-force attack attempts to guess credentials, but the primary observation here is the unauthorized source IP, not necessarily the method of credential compromise.
  • D. XSS is a client-side code injection attack, typically targeting users of a web application, not direct server access.

Unauthorized Access

Unauthorized access refers to gaining entry to a system, network, or data without explicit permission, often by bypassing security controls or exploiting vulnerabilities.

  • Involves illicit entry into restricted resources.
  • Can lead to data breaches, system compromise, or service disruption.
  • Often detected through anomaly detection, log analysis, or IDS/IPS alerts.

Memory trick: If it's not on the list, it's unauthorized access.

More Network Security questions