Question 1 of 30
In a corporate network, an incident response team is analyzing a series of suspicious packets captured during a network forensics investigation. The packets show a significant amount of traffic directed towards a specific internal server, which is not typically accessed by external users. The team identifies that the traffic is primarily composed of TCP packets with a source port of 443 and a destination port of 80. Given this scenario, what could be the most likely explanation for this unusual traffic pattern?
An attacker is using HTTPS to tunnel malicious HTTP requests to the internal server.
The internal server is misconfigured to accept HTTPS traffic on port 80.
Legitimate users are accessing the server through a proxy that modifies the port.
The network firewall is incorrectly logging HTTPS traffic as HTTP.

Preparing for CISCO 300-215 Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free