QuestionQ320
Detecting Exploitation and Covert Communications ToolsAn investigation identified several systems exhibiting suspicious activity. At regular intervals, the systems transmit data over port 80 to a different external host each time. What type of attack does this activity indicate?
- A An ICMP reverse shell
- B A user mode rootkit
- C A fast flux bot
- D A metamorphic worm
Community Discussion