A user downloaded software from an online forum. After the user installed the software, the security team observed external network traffic connecting to the user's computer on an uncommon port. Which of the following is the most likely explanation of this unauthorized connection?
Choose an answer
Tap an option to check your answer.
Correct answer: The software contained a backdoor..
Why this is the answer
The most likely explanation is that the software contained a backdoor. A backdoor is a hidden method of bypassing normal authentication or encryption in a computer system, allowing unauthorized remote access. The observed external network traffic on an uncommon port strongly suggests that the installed software created a covert channel for remote control or data exfiltration. A hidden keylogger would primarily capture keystrokes, not necessarily establish external connections on uncommon ports for remote access. Ransomware encrypts files and demands payment, which doesn't directly explain unauthorized external network traffic on an uncommon port for ongoing access. A fileless virus operates in memory without traditional file components, but the primary issue here is the unauthorized connection established by the downloaded software, pointing more directly to a backdoor.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed