Courseiva

CHFI Incident Response and First Responder Skills Practice Question

Exhibit

Refer to the exhibit.

C:\> netstat -ano
Active Connections

  Proto  Local Address          Foreign Address        State           PID
  TCP    192.168.1.100:1045     203.0.113.5:4444      ESTABLISHED     1234
  TCP    192.168.1.100:1046     192.168.1.1:443        ESTABLISHED     5678
  TCP    192.168.1.100:1047     10.0.0.1:22            ESTABLISHED     9012
  TCP    192.168.1.100:1048     198.51.100.7:80        TIME_WAIT       3456

Refer to the exhibit. During incident response, a first responder runs 'netstat -ano' on a compromised Windows system. Which connection is most likely to be the command-and-control (C2) channel and should be prioritized for isolation?

⚠ Common exam trap

EC-Council often tests the misconception that any external connection is suspicious, but the trap here is that candidates overlook the significance of the ESTABLISHED state and the specific port 4444, instead focusing on the IP address alone or mistaking a TIME_WAIT connection for an active threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

192.168.1.100:1045 to 203.0.113.5:4444 (ESTABLISHED)

Shows an established connection from the internal host (192.168.1.100) to an external IP (203.0.113.5) on TCP port 4444, which is commonly associated with Metasploit reverse shells and other C2 frameworks. The ESTABLISHED state indicates an active, ongoing session, making it the highest priority for isolation during incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    192.168.1.100:1045 to 203.0.113.5:4444 (ESTABLISHED)

    Why this is correct

    The established connection from the internal host to 203.0.113.5 on TCP port 4444 is a classic command-and-control indicator: port 4444 is the default listener port for Metasploit's Meterpreter reverse shell, and the destination is an external IP address that would not be in any internal allowlist. The ESTABLISHED state confirms an active, ongoing session, meaning the attacker likely already has a foothold and is maintaining control of the host. Moreover, 203.0.113.0/24 is a documentation range (TEST-NET-3), so its appearance in real traffic should immediately raise suspicion.

  • ✗

    192.168.1.100:1047 to 10.0.0.1:22 (ESTABLISHED)

    Why it's wrong here

    This connection to 10.0.0.1 on port 22 (SSH) is a legitimate administrative session to an internal server, not a C2 channel. The destination is a private RFC 1918 address, indicating the traffic stays within the trusted network, and SSH's strong encryption is appropriate for secure remote management. While SSH can be abused for tunneling, there is no evidence of that here—the source port is a normal ephemeral port, and the established state reflects a routine, authorized control session that aligns with standard operational behavior.

  • ✗

    192.168.1.100:1046 to 192.168.1.1:443 (ESTABLISHED)

    Why it's wrong here

    HTTPS to 192.168.1.1:443 is likely the internal gateway's management web interface or a captive portal, making this connection benign. The destination is the local router (default gateway) on a private IP, so the traffic never leaves the trusted segment, and the use of TLS provides confidentiality without indicating malicious intent. An established HTTPS connection to a known internal device is expected in a typical network and lacks the external destination and suspicious port pairing that would flag it as command-and-control.

  • ✗

    192.168.1.100:1048 to 198.51.100.7:80 (TIME_WAIT)

    Why it's wrong here

    This entry shows an HTTP request to 198.51.100.7 on port 80, but the TIME_WAIT state reveals that the connection is already completing its teardown, meaning no active data exchange is occurring. Short-lived HTTP connections like this are normal for web browsing or API calls, and TIME_WAIT simply indicates the client is waiting for a final ACK to ensure the connection closed cleanly. Command-and-control typically requires persistent, established sessions, so a connection in TIME_WAIT—especially to a documentation-range IP on a common web port—does not align with active attacker communication.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.