Which of the following is a sign of a network-based intrusion?

Prepare for the EC-Council Certified Ethical Hacker (CEH) Certification. Master concepts with flashcards and multiple choice questions, each enriching your understanding. Ready yourself to succeed in your exam!

Multiple Choice

Which of the following is a sign of a network-based intrusion?

Explanation:
When security monitoring looks for intrusions, spotting anomalies in how the network is used is a key signal. New or unusual protocols and services running indicate something outside the normal, expected environment is active. Attackers often attempt to bypass standard defenses or create covert channels by using uncommon or unexpected protocols and services, which stands out against a baseline of regular traffic. This kind of change directly points to potential unauthorized activity or a hidden foothold on the network. In contrast, increased bandwidth can happen from legitimate user activity or a DoS attack, regular traffic is just normal behavior, and high latency can be due to congestion, misconfigurations, or other non-security issues. The presence of new or unusual protocols and services is the strongest indicator among these options.

When security monitoring looks for intrusions, spotting anomalies in how the network is used is a key signal. New or unusual protocols and services running indicate something outside the normal, expected environment is active. Attackers often attempt to bypass standard defenses or create covert channels by using uncommon or unexpected protocols and services, which stands out against a baseline of regular traffic. This kind of change directly points to potential unauthorized activity or a hidden foothold on the network.

In contrast, increased bandwidth can happen from legitimate user activity or a DoS attack, regular traffic is just normal behavior, and high latency can be due to congestion, misconfigurations, or other non-security issues. The presence of new or unusual protocols and services is the strongest indicator among these options.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy