QuestionQ154
Logs and Network ForensicsYou are an information security analyst at a large pharmaceutical company. During a routine audit-log review, you notice a significant volume of egress traffic to various IP addresses on destination port 22 during off-peak hours. You research some of the IP addresses and find that many are in Eastern Europe. What is the most likely cause of this traffic?
- A The organization's primary internal DNS server has been compromised and is performing DNS zone transfers to malicious external entities
- B Data is being exfiltrated by an advanced persistent threat (APT)
- C Malicious software on internal system is downloading research data from partner SFTP servers in Eastern Europe
- D Internal systems are downloading automatic Windows updates
Community Discussion