ISC2 CC Network Security Practice Question
A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?
⚠ Common exam trap
CC often tests port number memorization; candidates may confuse port 25 with other common ports like 21 (FTP), 53 (DNS), or 80 (HTTP).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SMTP
SMTP (Simple Mail Transfer Protocol) operates over TCP port 25 by default for relaying and receiving email. Unusual outbound traffic on port 25 from an internal workstation often indicates a compromised host sending spam or a malware infection attempting to exfiltrate data via email. The other protocols listed use different default ports: FTP uses 20/21, DNS uses 53, and HTTP uses 80.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SMTP
Why this is correct
Port 25 is the standard TCP port for SMTP, used for sending and relaying email. Outbound traffic from an internal workstation to an external address on this port suggests the host is acting as a mail client or, more likely in this scenario, a compromised machine sending spam.
- ✗
FTP
Why it's wrong here
Port 25 carries SMTP, so FTP cannot explain this traffic; FTP uses ports 20 and 21 for data and control channels. FTP is tempting because it also moves data to external hosts, and it would be the answer had the capture shown port 21 commands or port 20 transfers.
- ✗
DNS
Why it's wrong here
DNS resolves names to IP addresses over port 53, so it cannot account for traffic on port 25. It is tempting because DNS queries also leave the internal network for external addresses, and DNS tunnelling can hide exfiltration, but that traffic still uses port 53 unless deliberately reconfigured.
- ✗
HTTP
Why it's wrong here
Port 25 carries SMTP, so HTTP traffic would not appear there; HTTP uses TCP 80 or 443. HTTP is tempting because it dominates network traffic and is frequently abused for command-and-control and data exfiltration, making it the right answer when unusual traffic targets web ports rather than mail submission.
Go deeper
Related to this question
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
DNS
DNS is the system that translates human-friendly domain names like example.com into machine-readable IP addresses so computers can find each other on a network.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.