ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 269 - CS0-003 discussion

Report
Export

A network analyst notices a long spike in traffic on port 1433 between two IP addresses on opposite sides of a WAN connection. Which of the following is the most likely cause?

A.
A local red team member is enumerating the local RFC1918 segment to enumerate hosts.
Answers
A.
A local red team member is enumerating the local RFC1918 segment to enumerate hosts.
B.
A threat actor has a foothold on the network and is sending out control beacons.
Answers
B.
A threat actor has a foothold on the network and is sending out control beacons.
C.
An administrator executed a new database replication process without notifying the SOC.
Answers
C.
An administrator executed a new database replication process without notifying the SOC.
D.
An insider threat actor is running Responder on the local segment, creating traffic replication.
Answers
D.
An insider threat actor is running Responder on the local segment, creating traffic replication.
Suggested answer: C

Explanation:

Port 1433 is commonly used by Microsoft SQL Server, which is a database management system. A spike in traffic on this port between two IP addresses on opposite sides of a WAN connection could indicate a database replication process, which is a way of copying and distributing data from one database server to another. This could be a legitimate activity performed by an administrator, but it should be communicated to the security operations center (SOC) to avoid confusion and false alarms.

asked 02/10/2024
Marcin Weglarski
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first