Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityEasy
A network security administrator is reviewing firewall logs and notices a high volume of outbound traffic on TCP port 25 from an internal server that typically does not send email. What type of activity is most likely indicated by this observation?
- ASecure file transfer using SFTP.
- BNormal web browsing activity by internal users.
- CA server attempting to send spam or malicious email.
- DLegitimate DNS queries to external servers.
Show answer & explanationAnswer & explanation
Correct answer: C. A server attempting to send spam or malicious email.
TCP port 25 is the standard port for Simple Mail Transfer Protocol (SMTP), used for sending email. A high volume of outbound traffic on this port from a non-mail server is highly suspicious and often indicates a compromised system being used to send spam or malware.
Why the other options are wrong
- A. SFTP uses TCP port 22 (SSH) for secure file transfers, not TCP port 25.
- B. Web browsing typically uses TCP port 80 (HTTP) or 443 (HTTPS).
- D. DNS queries typically use UDP port 53, not TCP port 25.
Common Network Ports
Standardized numerical labels assigned to specific network services, allowing devices to identify and direct traffic appropriately.
- Ports range from 0 to 65535.
- Well-known ports (0-1023) are assigned to common services.
- Understanding common ports is crucial for network security and troubleshooting.
Memory trick: Each door has a number, telling you what's inside.