SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium
A security operations center (SOC) analyst observes a sudden, sustained increase in network traffic originating from an internal server to various external IP addresses, primarily on port 53 (DNS) and port 443 (HTTPS). This traffic pattern is highly unusual for this particular server, which typically only communicates internally. What type of security event is this most indicative of?
- AData exfiltration
- BDenial of Service (DoS) attack
- CMalware infection or C2 communication
- DInsider threat activity
Show answer & explanationAnswer & explanation
Correct answer: C. Malware infection or C2 communication
A sudden, sustained increase in outbound traffic to unusual external destinations, especially on common ports like DNS and HTTPS, is a classic indicator of malware communicating with a Command and Control (C2) server. Malware often uses these ports to blend in with legitimate traffic.
Why the other options are wrong
- A. While data exfiltration involves outbound traffic, the description emphasizes 'various external IPs' and 'sustained increase' via common ports, which strongly points to C2 communication rather than just data transfer.
- B. A DoS attack usually involves incoming traffic overwhelming a target, not outbound traffic from an internal server.
- D. Insider threat activity could involve data exfiltration, but the pattern described (widespread, sustained, C2-like ports) is more characteristic of automated malware.
Command and Control (C2) Communication
The communication channel used by an attacker to remotely control compromised systems (bots) within a target network.
- Often uses common protocols (HTTP, HTTPS, DNS) to evade detection.
- Can involve regular 'beaconing' to check for instructions.
- Essential for attackers to maintain persistence and launch further attacks.
Memory trick: Unusual Traffic Patterns Signal Malicious Intents.