SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium

A security operations center (SOC) analyst observes a series of alerts indicating that an internal host is attempting to communicate with multiple external IP addresses over non-standard ports, immediately after a user opened an email attachment. This behavior is highly unusual for that host. Which of the following best describes the type of security event being observed?

  1. AFalse Positive
  2. BDistributed Denial of Service (DDoS)
  3. CMalware Infection
  4. DInsider Threat
Show answer & explanation

Correct answer: C. Malware Infection

The sequence of opening an email attachment followed by unusual outbound communication to multiple external IPs over non-standard ports strongly indicates a malware infection, likely a bot or command-and-control communication.

Why the other options are wrong

  • A. A false positive means the alert is incorrect; the observed behavior is clearly suspicious.
  • B. DDoS attacks involve overwhelming a target from many sources, not an internal host initiating unusual outbound connections.
  • D. While a user is involved, the behavior (unusual network traffic post-attachment) points to external control via malware, not necessarily malicious intent from the insider.

Malware Infection Indicators

Observable signs that a system has been compromised by malicious software.

  • Includes unusual network traffic, system performance degradation, unexpected pop-ups, and unauthorized file modifications.
  • Often initiated through phishing, malicious downloads, or exploiting vulnerabilities.
  • Requires prompt detection and remediation to prevent further damage.

Memory trick: Look for the 'digital symptoms' to diagnose the problem.

More Risk Identification, Monitoring, and Analysis questions