nerdexam
CompTIA

CS0-003 · Question #112

An analyst is reviewing the following output as part of an incident: Which of the following is MOST likely happening?

The correct answer is B. Information is leaking from the memory of host 10.20.30.40. 10.20.30.40 and 192.168.1.10 are both private IP addresses, which are used for internal networks. Since both IP's are private addresses, its not really exfiltrating data. Line 2 and 3 is what you want to be looking at. The request is Length 15, but ABCDEFJHIJ is only 10 CHARs…

Submitted by stefanr· Mar 6, 2026Incident Response and Management

Question

An analyst is reviewing the following output as part of an incident:

Which of the following is MOST likely happening?

Exhibit

CS0-003 question #112 exhibit

Options

  • AThe hosts are part of a reflective denial -of -service attack.
  • BInformation is leaking from the memory of host 10.20.30.40
  • CSensitive data is being exfilltrated by host 192.168.1.10.
  • DHost 291.168.1.10 is performing firewall port knocking.

How the community answered

(45 responses)
  • A
    22% (10)
  • B
    64% (29)
  • C
    4% (2)
  • D
    9% (4)

Explanation

10.20.30.40 and 192.168.1.10 are both private IP addresses, which are used for internal networks. Since both IP's are private addresses, its not really exfiltrating data. Line 2 and 3 is what you want to be looking at. The request is Length 15, but ABCDEFJHIJ is only 10 CHARs in length, but you can see the reply is giving additional information, based on the length.

Topics

#Network traffic analysis#Data exfiltration#DNS tunneling#Incident analysis

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice