List of questions
Related questions
Question 240 - CAS-004 discussion
A security operations center analyst is investigating anomalous activity between a database server and an unknown external IP address and gathered the following data:
* dbadmin last logged in at 7:30 a.m. and logged out at 8:05 a.m.
* A persistent TCP/6667 connection to the external address was established at 7:55 a.m. The connection is still active.
* Other than bytes transferred to keep the connection alive, only a few kilobytes of data transfer every hour since the start of the connection.
* A sample outbound request payload from PCAP showed the ASCII content: 'JOIN #community'.
Which of the following is the MOST likely root cause?
A.
A SQL injection was used to exfiltrate data from the database server.
B.
The system has been hijacked for cryptocurrency mining.
C.
A botnet Trojan is installed on the database server.
D.
The dbadmin user is consulting the community for help via Internet Relay Chat.
Your answer:
0 comments
Sorted by
Leave a comment first