Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A security analyst is reviewing network traffic and observes repeated, small, encrypted packets being sent from an internal host to an external IP address on a non-standard port (e.g., 53, 443, or 80) at regular intervals, even when there is no user activity. The destination IP address is not associated with any known legitimate services used by the organization. What type of network intrusion activity is most likely indicated by this behavior?
- ASQL injection attempt
- BMalware beaconing
- CDistributed Denial of Service (DDoS) attack
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: B. Malware beaconing
Malware beaconing involves infected hosts sending small, regular communications to a command-and-control server, often using common ports to evade detection. The described behavior perfectly matches this pattern of activity.
Why the other options are wrong
- A. SQL injection attempts target web applications and involve malicious input, not periodic network traffic to an external C2.
- C. A DDoS attack involves overwhelming a target with traffic, which is different from small, regular outbound packets from a single host.
- D. A brute-force attack typically involves many login attempts, not small, regular encrypted packets to an external IP.
Malware Beaconing
Malware beaconing is a technique where an infected host periodically sends small, often encrypted, packets to a command-and-control (C2) server to check for new instructions or confirm its active status.
- Periodic, small communications
- Often encrypted
- Uses common ports (e.g., 53, 80, 443) to blend in
- Indicates an active compromise and C2 communication
Memory trick: Malware 'Beacons' home, small and steady, to get its next orders.