An analyst notices there is an internal device sending HTTPS traffic with additional characters in the header to a known-malicious IP in another country. Which of the following describes what the analyst has noticed?
The correct answer is: A. Beaconing
This is the correct answer because beaconing refers to a situation where a device, often compromised, regularly sends network traffic to a remote server, typically to a known-malicious IP address. The additional characters in the header could be part of the communication used by malware to establish and maintain contact with a command-and-control (C&C) server. The regular, unusual traffic from an internal device to a foreign malicious IP is characteristic of beaconing, where the device "checks in" or sends signals to the attacker-controlled server.
Why the Other Options Are Incorrect:
Cross-site scripting
Buffer overflow
PHP traversal
No Payment Cards Needed
Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.
You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams