GCIH · Question #446
An investigation led to the identification of several systems showing suspicious activity. At regular time intervals, the systems send data over port 80 to different external hosts each time. Which…
The correct answer is C. A fast flux bot. Bots are software programs that perform some action on behalf of a human, typically with little or no human intervention. Attackers can use commonly open ports such as HTTP or HTTPS ports implement command and control sessions for their botnets. Using fast flux, where bots can…
Question
An investigation led to the identification of several systems showing suspicious activity. At regular time intervals, the systems send data over port 80 to different external hosts each time. Which type of attack is indicated by this activity?
Options
- AAn ICMP reverse shell
- BA user mode rootkit
- CA fast flux bot
- DA metamorphic worm
How the community answered
(51 responses)- A10% (5)
- B2% (1)
- C82% (42)
- D6% (3)
Explanation
Bots are software programs that perform some action on behalf of a human, typically with little or no human intervention. Attackers can use commonly open ports such as HTTP or HTTPS ports implement command and control sessions for their botnets. Using fast flux, where bots can communicate with a large number of external hosts, is one way attackers maintain access. Based on the details provided, there is no immediate indication of rootkits, metamorphic code or reverse shell activity.
Topics
Community Discussion
No community discussion yet for this question.