CS0-003 · Question #637
A company discovers that its proprietary information is being sold on the dark web. A security analyst uses threat hunting to search for signs of compromise. After running a network packet capture…
The correct answer is B. A threat actor is performing exfiltration over an alternative protocol. The packets show ICMP echo requests containing unusually large amounts of data in the payload. This pattern is characteristic of data exfiltration using ICMP as an alternative protocol, allowing an attacker to move proprietary information out of the network while avoiding…
Question
A company discovers that its proprietary information is being sold on the dark web. A security analyst uses threat hunting to search for signs of compromise. After running a network packet capture tool, the analyst identifies millions of packets similar to the following:
The analyst does not detect or identify any other abnormalities. Which of the following is most likely the malicious activity in this scenario?
Exhibit
Options
- AAn insider is using an IP command-and-control to sell proprietary information.
- BA threat actor is performing exfiltration over an alternative protocol.
- CA machine was infected with a virus that is trying to propagate.
- DA hacktivist is conducting an ICMP DDoS attack against the company.
How the community answered
(49 responses)- A10% (5)
- B67% (33)
- C18% (9)
- D4% (2)
Explanation
The packets show ICMP echo requests containing unusually large amounts of data in the payload. This pattern is characteristic of data exfiltration using ICMP as an alternative protocol, allowing an attacker to move proprietary information out of the network while avoiding traditional detection mechanisms.
Topics
Community Discussion
No community discussion yet for this question.
