Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 109 Topic 11 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 109 Topic 11 Discussion

CS0-003 Exam Topic 11 Question 109 Discussion:
Question #: 109
Topic #: 11

A company discovers that its proprietary information is being sold on the dark web. A security analyst uses threat hunting to search for signs of compromise. After running a network packet capture tool, the analyst identifies millions of packets similar to the following:

Internet Protocol Version 4, src: 192.168.1.2, dst: 104.21.75.76

Internet Control Message Protocol

Type: 8 Echo request

Code: 0

Checksum: 0x34db [correct]

Sequence number: 3362

No response seen

Data: 64 bytes

Data payload: 0e1bS8…157ea2054af44…9865b34857a05…24b45824…

The analyst does not detect or identify any other abnormalities. Which of the following is most likely the malicious activity in this scenario?


A.

An insider is using an IP command-and-control channel to sell proprietary information.


B.

A threat actor is performing exfiltration over an alternative protocol.


C.

A machine was infected with a virus that is trying to propagate.


D.

A hacktivist is conducting an ICMP DDoS attack against the company.


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.