GCIH · Question #487
You are investigating an incident on a workstation that you suspect is compromised after the user opened an executable in an email. The workstation is used for email, internet access, and office…
The correct answer is C. 112.101.64.1. The most suspect connection is the one with the local port 5900 open with an established connection. This indicates the local machine is running a VNC server, which has remote GUI and control capabilities. Ports 443 and 80 are not unusual to have open, and were established by…
Question
You are investigating an incident on a workstation that you suspect is compromised after the user opened an executable in an email. The workstation is used for email, internet access, and office applications; it is never remotely accessed. You run netstat -n to view the current network connections. Below is a partial capture of the output. Which IP address is most suspect and should be investigated first?
Exhibit
Options
- A10.0.0.15
- B98.138.253.109
- C112.101.64.1
- D74.125.228.36
How the community answered
(43 responses)- A9% (4)
- B2% (1)
- C84% (36)
- D5% (2)
Explanation
The most suspect connection is the one with the local port 5900 open with an established connection. This indicates the local machine is running a VNC server, which has remote GUI and control capabilities. Ports 443 and 80 are not unusual to have open, and were established by the local machine, which normally indicates web browsing. 10.0.0.15 is IP address of the machine you're working on.
Topics
Community Discussion
No community discussion yet for this question.
