Q34Network Intrusion Analysis
Refer to the exhibit. A network administrator is examining captured traffic to investigate suspicious network activity. An engineer observes abnormal behavior and finds that the default user agent appears in the headers of requests and transmitted data. What is happening?
← → navigate · a answer
Community votes
Discussion · 6
B 4
Selected Answer: B
B. Indicators of data exfiltration: HTTP requests must be plain text. Using default user agents is a common tactic attackers use to blend in with normal web traffic and avoid detection. When paired with plain text HTTP requests, this behavior can indicate data exfiltration. The attacker is using a common user agent to evade detection, and plain text HTTP requests make it easier to hide the data being exfiltrated.
3
I dont think this is B, both IPs are internal and the data are going back and forth in the same requests
3
Correct ANS=C
C 3
Selected Answer: C
id' say C
C 1
Selected Answer: C
Correct answer is C
B 1
Selected Answer: B
The right answer is B. indicators of data exfiltration: HTTP requests must be plain text.
- Data Exfiltration over HTTP: The prompt points out that abnormal data is being transmitted with unencrypted, plain-text HTTP requests and a default user-agent. Attackers often use standard, built-in system tools (like curl, wget, or default scripting library headers) to exfiltrate stolen staging data straight to an outside web server over open ports like 80 and neatly get around strict egress network firewalls.
- Plain Text Traffic: Since the data is sent over a basic unencrypted protocol (HTTP), an analyst using a network packet analyzer can directly see the cleartext payload strings being moved in the streams, confirming it as an indicator of data exfiltration.