🔥 3-day streak
Cisco CCNP Security SCOR (350-701)68 / 146
Question 68 of 146

A security analyst reviewing Secure Network Analytics flow records notices that several internal hosts are maintaining persistent outbound TCP sessions to an external server on port 6667. The sessions show low-volume, bidirectional text-based traffic with periodic short bursts, and the destination is not on any approved application list. Which exfiltration or command-and-control technique is most consistent with this behavior?

Reviewed for accuracy · Report an issueNext question