Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

Exhibit

[2025-03-05 14:32:18] BLOCK: src=10.0.2.100 dst=203.0.113.50 port=4444 proto=TCP rule=IDS_Alert_Signature
[2025-03-05 14:32:19] BLOCK: src=10.0.2.100 dst=203.0.113.51 port=4444 proto=TCP
[2025-03-05 14:32:20] BLOCK: src=10.0.2.100 dst=203.0.113.52 port=4444 proto=TCP

Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?

⚠ Common exam trap

ISC2 often tests the distinction between outbound connection attempts (indicative of malware C2) and inbound connection attempts (indicative of remote access or scanning), leading candidates to mistakenly choose remote desktop or port scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server is infected with malware

Repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port are a classic indicator of malware command-and-control (C2) activity. Malware often uses non-standard ports to evade detection and establish outbound communication with an external attacker. This behavior is not typical of legitimate services, which use well-known ports and protocols.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server is being used for remote desktop access

    Why it's wrong here

    Remote desktop access uses TCP 3389 and is inbound to the server, not repeated outbound attempts to many external IPs on a non-standard port. It is tempting because RDP traffic can be tunnelled over arbitrary ports, but that still terminates on a listening service, not fan-out connections to numerous external hosts.

  • ✗

    The server is performing a port scan

    Why it's wrong here

    A port scan originates from the scanning host and targets many destination ports on one or more hosts; here the internal server repeatedly initiates outbound connections to external addresses on a single non-standard port, which is beaconing behaviour. Port scanning suits an interpretation where one source probes sequential ports across targets.

  • ✗

    The server is a legitimate mail server

    Why it's wrong here

    Mail servers use well-known ports such as 25, 465 and 587; repeated connections to external addresses on a non-standard port do not match SMTP behaviour. Legitimate mail traffic would be the interpretation when the exhibit shows standard mail ports and expected relay destinations.

  • ✓

    The server is infected with malware

    Why this is correct

    Repeated outbound connections to external IPs on a non-standard port indicate beaconing or command-and-control traffic, characteristic of malware on the internal server. The stem's pattern of repeated attempts, rather than a single connection, distinguishes malicious callback behaviour from legitimate application traffic.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.