nerdexam
GIAC

GCIH · Question #487

You are investigating an incident on a workstation that you suspect is compromised after the user opened an executable in an email. The workstation is used for email, internet access, and office…

The correct answer is C. 112.101.64.1. The most suspect connection is the one with the local port 5900 open with an established connection. This indicates the local machine is running a VNC server, which has remote GUI and control capabilities. Ports 443 and 80 are not unusual to have open, and were established by…

Incident Response & Cyber Kill Chain

Question

You are investigating an incident on a workstation that you suspect is compromised after the user opened an executable in an email. The workstation is used for email, internet access, and office applications; it is never remotely accessed. You run netstat -n to view the current network connections. Below is a partial capture of the output. Which IP address is most suspect and should be investigated first?

Exhibit

GCIH question #487 exhibit

Options

  • A10.0.0.15
  • B98.138.253.109
  • C112.101.64.1
  • D74.125.228.36

How the community answered

(43 responses)
  • A
    9% (4)
  • B
    2% (1)
  • C
    84% (36)
  • D
    5% (2)

Explanation

The most suspect connection is the one with the local port 5900 open with an established connection. This indicates the local machine is running a VNC server, which has remote GUI and control capabilities. Ports 443 and 80 are not unusual to have open, and were established by the local machine, which normally indicates web browsing. 10.0.0.15 is IP address of the machine you're working on.

Topics

#netstat#suspicious network connections#compromised workstation#C2 traffic identification

Community Discussion

No community discussion yet for this question.

Full GCIH Practice