Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 6 Question 7 Discussion

Refer to the exhibit.A security team detects a spike in traffic from the company web server. After further investigation, the team discovered that multiple connections have been established from the server to different IP addresses, but the web server logs contain both expected traffic and DDoS traffic. Which attribute must the team use to further filter the logs?
A) connection status
B) destination port
C) IP address of the web server
D) protocol

Cisco 300-220 Exam - Topic 6 Question 7 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 7
Topic #: 6
[All 300-220 Questions]

Refer to the exhibit.

A security team detects a spike in traffic from the company web server. After further investigation, the team discovered that multiple connections have been established from the server to different IP addresses, but the web server logs contain both expected traffic and DDoS traffic. Which attribute must the team use to further filter the logs?

Show Suggested Answer Hide Answer
Suggested Answer: A

The correct answer is Connection status. In this scenario, the key challenge for the security team is differentiating legitimate outbound traffic from malicious or DDoS-related traffic originating from the same web server. Since both types of traffic coexist in the logs, analysts must rely on an attribute that meaningfully distinguishes normal behavior from abnormal patterns.

The exhibit shows numerous TCP connections from the web server to many different external IP addresses, with varying TCP states such as ESTABLISHED, TIME_WAIT, and FIN_WAIT. These connection states are highly valuable for threat hunting and network analysis. During DDoS activity---especially reflected or amplification-style attacks, or when a server is abused as part of an attack---connections often remain half-open, rapidly transition to TIME_WAIT, or fail to fully establish. In contrast, legitimate web traffic typically results in stable, short-lived ESTABLISHED sessions that follow predictable patterns.

Option B (destination port) is not useful here because most web traffic---both legitimate and malicious---commonly uses ports 80 or 443. Option C (IP address of the web server) provides no filtering value because all traffic already originates from that server. Option D (protocol) is also ineffective, as both normal and DDoS traffic in this case use TCP.

From a professional SOC and threat hunting standpoint, connection state analysis is a foundational technique for detecting volumetric attacks, beaconing behavior, and abnormal session churn. By filtering logs based on connection status, analysts can quickly isolate suspicious patterns such as excessive short-lived connections, abnormal teardown behavior, or asymmetric session states that are characteristic of DDoS-related activity.

This approach aligns with mature threat hunting practices: when indicators overlap, pivot to behavioral attributes. Connection status provides the necessary behavioral signal to separate expected traffic from attack traffic and supports faster, more accurate incident response.


Contribute your Thoughts:

0/2000 characters
Bettina
3 days ago
Destination port could help if we know which services are targeted.
upvoted 0 times
...
Barbra
8 days ago
Filtering by IP can reveal patterns in the DDoS attack.
upvoted 0 times
...
Glory
13 days ago
Protocol is important too, but IP seems more direct.
upvoted 0 times
...
Son
19 days ago
Connection status might show if it's legit or not.
upvoted 0 times
...
Stephaine
24 days ago
I agree, but destination port could also narrow it down.
upvoted 0 times
...
Janae
29 days ago
I think we should filter by IP address. It helps identify the source.
upvoted 0 times
...
Ressie
1 month ago
Not sure if destination port is the best choice, though.
upvoted 0 times
...
Leonard
1 month ago
Filtering by IP address of the web server seems obvious.
upvoted 0 times
...
Cherry
1 month ago
Surprised they didn't mention the protocol!
upvoted 0 times
...
Charlene
2 months ago
I think the connection status is more relevant here.
upvoted 0 times
...
Andra
2 months ago
Definitely need to check the destination port.
upvoted 0 times
...
Richelle
2 months ago
Not sure if destination port is the best choice, though.
upvoted 0 times
...
Sheron
2 months ago
Filtering by IP address of the web server seems obvious.
upvoted 0 times
...
Blair
2 months ago
Surprised they didn't mention the protocol!
upvoted 0 times
...
Tina
4 months ago
I think the connection status is more relevant here.
upvoted 0 times
...
Nida
4 months ago
Definitely need to check the destination port.
upvoted 0 times
...
Lucy
5 months ago
I lean towards using the protocol attribute. It seems like it could help us distinguish between different types of traffic more effectively.
upvoted 0 times
...
Jade
5 months ago
I feel like the IP address of the web server could be useful, but it might not give us the full picture since we need to see the connections made.
upvoted 0 times
...
Luis
5 months ago
I'm not entirely sure, but I remember something about filtering by connection status in similar practice questions. That might narrow it down.
upvoted 0 times
...
Floyd
5 months ago
I think we should look at the destination port. It might help us identify if the traffic is legitimate or part of the DDoS attack.
upvoted 0 times
...

Save Cancel