Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 671 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 671
Topic #: 1
[All 312-49v10 Questions]

You are an information security analyst at a large pharmaceutical company. While performing a routine review of audit logs, you have noticed a significant amount of egress traffic to various IP addresses on destination port 22 during off-peak hours. You researched some of the IP addresses and found that many of them are in Eastern Europe. What is the most likely cause of this traffic?

  • A. The organization's primary internal DNS server has been compromised and is performing DNS zone transfers to malicious external entities
  • B. Data is being exfiltrated by an advanced persistent threat (APT)
  • C. Malicious software on internal system is downloading research data from partner SFTP servers in Eastern Europe
  • D. Internal systems are downloading automatic Windows updates
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gooftroop
Highly Voted 1 year, 10 months ago
B. Data is being exfiltrated by an advanced persistent threat (APT)
upvoted 6 times
global88
1 year, 8 months ago
correct
upvoted 1 times
...
...
jingu_bingo
Most Recent 5 months, 3 weeks ago
Selected Answer: B
Keyword is "egress", which means "to go" or to "come out". Yes SFTP runs on port 22 (choice C) but choice C is downloading or "coming in". B is the only valid case. I will 'egress' to my parents soon.
upvoted 1 times
...
Elb
6 months ago
Data egress refers to the process of sending data out...
upvoted 1 times
...
marymayhem
1 year, 4 months ago
Selected Answer: B
Likely B, egress traffic suggests exfiltration rather than incoming downloads.
upvoted 2 times
...
franintech
1 year, 9 months ago
Option C is a possibility, but the use of port 22 (which is commonly associated with SSH) connections) suggests that the egress traffic could be the result of data exfiltration by an advanced persistent threat (APT) or unauthorized access. Thus, option B (Data is being exfiltrated by an advanced persistent threat (APT))
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...