SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium
A security operations center (SOC) analyst observes a series of alerts indicating that an internal host is attempting to communicate with multiple external IP addresses over non-standard ports, immediately after a user opened an email attachment. This behavior is highly unusual for that host. Which of the following best describes the type of security event being observed?
- AFalse Positive
- BDistributed Denial of Service (DDoS)
- CMalware Infection
- DInsider Threat
Show answer & explanationAnswer & explanation
Correct answer: C. Malware Infection
The sequence of opening an email attachment followed by unusual outbound communication to multiple external IPs over non-standard ports strongly indicates a malware infection, likely a bot or command-and-control communication.
Why the other options are wrong
- A. A false positive means the alert is incorrect; the observed behavior is clearly suspicious.
- B. DDoS attacks involve overwhelming a target from many sources, not an internal host initiating unusual outbound connections.
- D. While a user is involved, the behavior (unusual network traffic post-attachment) points to external control via malware, not necessarily malicious intent from the insider.
Malware Infection Indicators
Observable signs that a system has been compromised by malicious software.
- Includes unusual network traffic, system performance degradation, unexpected pop-ups, and unauthorized file modifications.
- Often initiated through phishing, malicious downloads, or exploiting vulnerabilities.
- Requires prompt detection and remediation to prevent further damage.
Memory trick: Look for the 'digital symptoms' to diagnose the problem.