Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsEasy

A network administrator is reviewing security logs and notices a large number of connection attempts to various internal servers from an external IP address, all targeting common service ports like 21, 23, 80, and 443. These attempts are not resulting in successful logins but are occurring in a systematic, automated fashion across a wide range of IP addresses within the network. What type of attack is most likely being attempted?

  1. APort scanning
  2. BSQL injection
  3. CMan-in-the-Middle (MitM) attack
  4. DDenial-of-Service (DoS) attack
Show answer & explanation

Correct answer: A. Port scanning

Port scanning involves systematically checking open ports on a host or network to discover available services. The description of numerous connection attempts to common service ports from an external IP in an automated fashion perfectly matches this activity.

Why the other options are wrong

  • B. SQL injection targets database vulnerabilities through web application inputs, not by scanning general network ports.
  • C. A MitM attack intercepts communication between two parties, which is not indicated by probing common ports.
  • D. A DoS attack aims to make a service unavailable, not primarily to discover open ports.

Port Scanning

Port scanning is a technique used to identify open ports and services on a network host. Attackers use it to discover potential entry points and vulnerabilities.

  • Identifies open ports and services.
  • Often a precursor to other attacks.
  • Can be detected by intrusion detection systems.

Memory trick: Reconnaissance is like a spy casing a joint before the big heist.

More Security Fundamentals questions