nerdexam
Cisco

350-201 · Question #27

An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that the file hash is…

The correct answer is A. Command and Control, Application Layer Protocol, Duqu. https://attack.mitre.org/software/S0038/

Network Intrusion Analysis

Question

An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that the file hash is associated with Duqu malware. Which tactics, techniques, and procedures align with this analysis?

Options

  • ACommand and Control, Application Layer Protocol, Duqu
  • BDiscovery, Remote Services: SMB/Windows Admin Shares, Duqu
  • CLateral Movement, Remote Services: SMB/Windows Admin Shares, Duqu
  • DDiscovery, System Network Configuration Discovery, Duqu

How the community answered

(48 responses)
  • A
    60% (29)
  • B
    6% (3)
  • C
    13% (6)
  • D
    21% (10)

Explanation

https://attack.mitre.org/software/S0038/

Topics

#MITRE ATT&CK#command and control#application layer protocol#Duqu malware

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice