Question 791

An AWS security operations team receives an alert regarding abnormal outbound traffic from an EC2 instance. The instance, which previously handled backend microservices, begins transmitting encrypted data packets to an external domain. Upon deeper investigation, it is discovered that the external domain resolves to a Dropbox account not associated with the organization. Network flow logs confirm a consistent pattern of data transfers to this destination during off-peak hours. Further forensic analysis reveals that a malicious executable was silently installed on the instance, which modifies the sync configuration of the Dropbox client to use the attacker's access token. This enables the compromised EC2 instance to automatically sync selected data folders with the attacker's Dropbox storage, bypassing traditional perimeter defenses. What type of attack has likely occurred?
  • Question 792

    what firewall evasion scanning technique make use of a zombie system that has low network activity as well as its fragment identification numbers?
  • Question 793

    Which of the following DoS tools is used to attack target web applications by starvation of available sessions on the web server? The tool keeps sessions at halt using never-ending POST transmissions and sending an arbitrarily large content-length header value.
  • Question 794

    Which utility will tell you in real time which ports are listening or in another state?
  • Question 795

    An ethical hacker is auditing a hospital's wireless network, which is currently secured with WPA encryption using TKIP. The hacker successfully demonstrates packet-injection and decryption attacks on the network. Which vulnerability in WPA most likely allowed these attacks to succeed?