ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security analyst established a baseline for a Linux bastion host showing fewer than 50 000 outbound packets per hour, almost all SSH traffic to internal subnets. Three weeks later, VPC Flow Logs reveal 1.8 million outbound packets in 15 minutes to random public IP addresses on TCP port 445. How should the analyst classify this activity?
Harmless internal file-sharing traffic; port 445 traffic is typical inside the VPC.
An anomaly suggesting the instance may be compromised and attempting data exfiltration or worm propagation.
Expected overhead from the Amazon CloudWatch agent sending enhanced monitoring metrics.
A normal burst caused by AWS Systems Manager Patch Manager downloading updates.
The sudden, sustained spike in outbound packets to external IP addresses on port 445 deviates sharply from the previously recorded baseline for the bastion host. Because port 445 is commonly associated with SMB file-sharing worms and data exfiltration, this pattern is a strong indicator of compromise rather than normal operational activity. Scheduled patching via AWS Systems Manager, CloudWatch agent heartbeats, or internal Windows file-share traffic would not generate unsolicited, high-volume SMB connections to the internet, so those explanations are unlikely given the baseline.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is port 445 used for in computer networks?
Open an interactive chat with Bash
How do VPC Flow Logs help detect anomalies in network traffic?
Open an interactive chat with Bash
What measures can be taken to protect Linux bastion hosts from compromise?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .