CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 18 Topic 2 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 18 Topic 2 Discussion

CS0-003 Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

A systems administrator is reviewing after-hours traffic flows from data center servers and sees regular, outgoing HTTPS connections from one of the servers to a public IP address. The server should not be making outgoing connections after hours. Looking closer, the administrator sees this traffic pattern around the clock during work hours as well. Which of the following is the most likely explanation?


A.

Command-and-control beaconing activity


B.

Data exfiltration


C.

Anomalous activity on unexpected ports


D.

Network host IP address scanning


E.

A rogue network device


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.