exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 396 discussion

Actual exam question from CompTIA's CS0-003
Question #: 396
Topic #: 1
[All CS0-003 Questions]

A security analyst runs tcpdump on the 10.203.10.22 machine and observes thousands of packets as shown below:



Which of the following activities explains the tcpdump output?

  • A. Incoming nmap -sA scan
  • B. hping3 --udp scan over the network
  • C. C2 communications leaving the network
  • D. Malware beaconing
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BlackSkullz
4 days, 2 hours ago
Selected Answer: A
This is an nmap -sA scan, or an ACK scan, from another local workstation. It's coming from one port on the source IP and being received by multiple ports on the destination/victim IP because it's checking for open ports. Both IPs are on the same network so there isn't any malware beaconing or C2 communication. And given that these are ack packets, it isn't anything UDP related
upvoted 2 times
BlackSkullz
4 days, 2 hours ago
I mistyped on the "checking for open ports" part. The purpose of an ACK scan is usually to identify which ports are reachable through a firewall. No response indicates that the port is filtered and the traffic was blocked. A response, typically a RST packet, indicates that the port is unfiltered and was allowed through the firewall
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago