A company web server is initiating outbound traffic to a low-reputation, public IP on non-standard pat. The web server is used to present an unauthenticated page to clients who upload images the company. An analyst notices a suspicious process running on the server hat was not created by the company development team. Which of the following is the most likely explanation for his security incident?
- AA web shell has been deployed to the server through the page. (correct answer)
- BA vulnerability has been exploited to deploy a worm to the server.
- CMalicious insiders are using the server to mine cryptocurrency.
- DAttackers have deployed a rootkit Trojan to the server over an exposed RDP port.
Reveal answer & explanationHide answer
The correct answer is A. Option A: A web shell has been deployed to the server through the page. This option keeps traffic private / properly secured as required.
