CAS-005 · Question #166
A small number but steady series of attempts to breach the network has been occurring over a long period of time. During an investigation, a SOC analyst finds that traffic is exiting the network to kn
The correct answer is A. Supply chain. The presence of a rogue network device sending traffic to malicious hosts over a long period strongly indicates a supply chain attack, where a malicious component was introduced into the network.
Question
A small number but steady series of attempts to breach the network has been occurring over a long period of time. During an investigation, a SOC analyst finds that traffic is exiting the network to known malicious hosts and is originating from a rogue network device. Which of the following attack vectors is most likely being used to breach the network?
Options
- ASupply chain
- BBuffer overflow
- CSocial engineering
- DRansomware
How the community answered
(36 responses)- A78% (28)
- B8% (3)
- C11% (4)
- D3% (1)
Why each option
The presence of a rogue network device sending traffic to malicious hosts over a long period strongly indicates a supply chain attack, where a malicious component was introduced into the network.
A supply chain attack involves targeting an organization by compromising less secure elements in its supply chain, such as introducing a rogue device or backdoored software before it reaches the intended victim.
A buffer overflow is a specific type of software vulnerability exploitation, not an attack vector involving rogue network devices and long-term exfiltration.
Social engineering typically targets individuals to gain access or information, and while it could lead to a device being installed, the description of 'rogue network device' and long-term, steady exfiltration points more to a pre-meditated insertion rather than just user manipulation.
Ransomware is a type of malware that encrypts data for a ransom, and while it could be delivered via various means, it does not directly describe the 'rogue network device' and 'traffic exiting to malicious hosts' scenario as the primary attack vector.
Concept tested: Supply chain attack characteristics
Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/design-supply-chain-security
Community Discussion
No community discussion yet for this question.