A security analyst is investigating an application server and discovers that software on the server is behaving abnormally. The software normally runs batch jobs locally and does not generate traffic, but the process is now generating outbound traffic over random high ports. Which of the following vulnerabilities has likely been exploited in this software?
Choose an answer
Tap an option to check your answer.
Correct answer: Memory injection.
Why this is the answer
Memory injection, specifically code injection, is the most likely vulnerability. This attack involves injecting malicious code into a running process's memory space, causing it to execute arbitrary commands, such as establishing outbound connections on random high ports, which is abnormal behavior for a batch job. A race condition involves timing-dependent errors and wouldn't directly cause outbound traffic. Sideloading refers to installing applications from unofficial sources, not an exploit of a running process. SQL injection targets databases and manipulates queries, not the execution of arbitrary code leading to network traffic from a non-database process.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed