nerdexam
CompTIA

SY0-301 · Question #273

Which of the following protocols is the security administrator observing in this packet capture? 12:33:43, SRC 192.168.4.3:3389, DST 10.67.33.20:8080, SYN/ACK

The correct answer is B. RDP. The key indicator in this packet capture is the source port 3389. Port 3389 is the well-known default port for RDP (Remote Desktop Protocol), which is used to remotely access and control Windows-based systems. The destination port 8080 is a common alternate HTTP port, but port…

Security operations

Question

Which of the following protocols is the security administrator observing in this packet capture? 12:33:43, SRC 192.168.4.3:3389, DST 10.67.33.20:8080, SYN/ACK

Options

  • AHTTPS
  • BRDP
  • CHTTP
  • DSFTP

How the community answered

(26 responses)
  • B
    88% (23)
  • C
    4% (1)
  • D
    8% (2)

Explanation

The key indicator in this packet capture is the source port 3389. Port 3389 is the well-known default port for RDP (Remote Desktop Protocol), which is used to remotely access and control Windows-based systems. The destination port 8080 is a common alternate HTTP port, but port identification focuses on the registered service port, which in this case is the source (3389 = RDP). HTTPS uses port 443, HTTP uses port 80, and SFTP uses port 22.

Topics

#packet analysis#RDP#port numbers#network protocols

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice