CHFI Incident Response and First Responder Skills Practice Question
Exhibit
Refer to the exhibit. C:\> netstat -ano Active Connections Proto Local Address Foreign Address State PID TCP 192.168.1.100:1045 203.0.113.5:4444 ESTABLISHED 1234 TCP 192.168.1.100:1046 192.168.1.1:443 ESTABLISHED 5678 TCP 192.168.1.100:1047 10.0.0.1:22 ESTABLISHED 9012 TCP 192.168.1.100:1048 198.51.100.7:80 TIME_WAIT 3456
Refer to the exhibit. During incident response, a first responder runs 'netstat -ano' on a compromised Windows system. Which connection is most likely to be the command-and-control (C2) channel and should be prioritized for isolation?
⚠ Common exam trap
EC-Council often tests the misconception that any external connection is suspicious, but the trap here is that candidates overlook the significance of the ESTABLISHED state and the specific port 4444, instead focusing on the IP address alone or mistaking a TIME_WAIT connection for an active threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
192.168.1.100:1045 to 203.0.113.5:4444 (ESTABLISHED)
Shows an established connection from the internal host (192.168.1.100) to an external IP (203.0.113.5) on TCP port 4444, which is commonly associated with Metasploit reverse shells and other C2 frameworks. The ESTABLISHED state indicates an active, ongoing session, making it the highest priority for isolation during incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
192.168.1.100:1045 to 203.0.113.5:4444 (ESTABLISHED)
Why this is correct
The established connection from the internal host to 203.0.113.5 on TCP port 4444 is a classic command-and-control indicator: port 4444 is the default listener port for Metasploit's Meterpreter reverse shell, and the destination is an external IP address that would not be in any internal allowlist. The ESTABLISHED state confirms an active, ongoing session, meaning the attacker likely already has a foothold and is maintaining control of the host. Moreover, 203.0.113.0/24 is a documentation range (TEST-NET-3), so its appearance in real traffic should immediately raise suspicion.
- ✗
192.168.1.100:1047 to 10.0.0.1:22 (ESTABLISHED)
Why it's wrong here
This connection to 10.0.0.1 on port 22 (SSH) is a legitimate administrative session to an internal server, not a C2 channel. The destination is a private RFC 1918 address, indicating the traffic stays within the trusted network, and SSH's strong encryption is appropriate for secure remote management. While SSH can be abused for tunneling, there is no evidence of that here—the source port is a normal ephemeral port, and the established state reflects a routine, authorized control session that aligns with standard operational behavior.
- ✗
192.168.1.100:1046 to 192.168.1.1:443 (ESTABLISHED)
Why it's wrong here
HTTPS to 192.168.1.1:443 is likely the internal gateway's management web interface or a captive portal, making this connection benign. The destination is the local router (default gateway) on a private IP, so the traffic never leaves the trusted segment, and the use of TLS provides confidentiality without indicating malicious intent. An established HTTPS connection to a known internal device is expected in a typical network and lacks the external destination and suspicious port pairing that would flag it as command-and-control.
- ✗
192.168.1.100:1048 to 198.51.100.7:80 (TIME_WAIT)
Why it's wrong here
This entry shows an HTTP request to 198.51.100.7 on port 80, but the TIME_WAIT state reveals that the connection is already completing its teardown, meaning no active data exchange is occurring. Short-lived HTTP connections like this are normal for web browsing or API calls, and TIME_WAIT simply indicates the client is waiting for a final ACK to ensure the connection closed cleanly. Command-and-control typically requires persistent, established sessions, so a connection in TIME_WAIT—especially to a documentation-range IP on a common web port—does not align with active attacker communication.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.