nerdexam
GAQM

CPEH-001 · Question #141

You are working as a Security Analyst in a company XYZ that owns the whole subnet range of 23.0.0.0/8 and 192.168.0.0/8. While monitoring the data, you find a high number of outbound connections…

The correct answer is A. Botnet Attack. See the full explanation below for the reasoning.

Question

You are working as a Security Analyst in a company XYZ that owns the whole subnet range of 23.0.0.0/8 and 192.168.0.0/8. While monitoring the data, you find a high number of outbound connections. You see that IP's owned by XYZ (Internal) and private IP's are communicating to a Single Public IP. Therefore, the Internal IP's are sending data to the Public IP. After further analysis, you find out that this Public IP is a blacklisted IP, and the internal communicating devices are compromised. What kind of attack does the above scenario depict?

Exhibit

CPEH-001 question #141 exhibit

Options

  • ABotnet Attack
  • BSpear Phishing Attack
  • CAdvanced Persistent Threats
  • DRootkit Attack

How the community answered

(17 responses)
  • A
    71% (12)
  • B
    6% (1)
  • C
    18% (3)
  • D
    6% (1)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice