A company web server is initiating outbound traffic to a low-reputation, public IP on non-standard pat. The web server is used to present an unauthenticated page to clients who upload images the company. An analyst notices a suspicious process running on the server hat was not created by the company development team. Which of the following is the most likely explanation for his security incident?
Choose an answer
Tap an option to check your answer.
Correct answer: A web shell has been deployed to the server through the page..
Why this is the answer
The most likely explanation is a web shell deployed through the page. The web server handles image uploads, a common vector for attackers to upload malicious files, including web shells. A web shell allows attackers to remotely execute commands on the server, explaining the suspicious outbound traffic to a low-reputation IP and the unknown process. A worm is less likely as it typically self-propagates, which isn't directly indicated by the scenario. While cryptocurrency mining is possible, the primary indicators (outbound traffic to a low-reputation IP, suspicious process) point more strongly to direct attacker control via a web shell. An exposed RDP port and rootkit Trojan are also possibilities, but the image upload functionality provides a more direct and common path for initial compromise leading to a web shell, which then facilitates the observed activities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed