Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 112-51 Topic 6 Question 33 Discussion

Actual exam question for Eccouncil's 112-51 exam
Question #: 33
Topic #: 6
[All 112-51 Questions]

Barbara, a security professional, was monitoring the loT traffic through a security solution. She identified that one of the infected devices is trying to connect with other loT devices and spread malware onto the network. Identify the port number used by the malware to spread the infection to other loT devices.

Show Suggested Answer Hide Answer
Suggested Answer: D

Port 48101 is the port number used by the malware to spread the infection to other loT devices. This port is associated with the Mirai botnet, which is one of the most notorious loT malware that targets vulnerable loT devices and turns them into a network of bots that can launch distributed denial-of-service (DDoS) attacks. Mirai scans the internet for loT devices that use default or weak credentials and infects them by logging in via Telnet or SSH. Once infected, the device connects to a command and control (C&C) server on port 48101 and waits for instructions. The C&C server can then direct the botnet to attack a target by sending TCP, UDP, or HTTP requests. Mirai has been responsible for some of the largest DDoS attacks in history, such as the one that disrupted Dyn DNS in 2016 and affected major websites like Twitter, Netflix, and Reddit. Reference:

Mirai (malware), Wikipedia, March 16, 2021

Mirai Botnet: A History of the Largest loT Botnet Attacks, Imperva, December 10, 2020

Mirai Botnet: How loT Devices Almost Brought Down the Internet, Cloudflare, March 17, 2021


Contribute your Thoughts:

Andra
1 months ago
This question is making me hungry. I could really go for a port-er house steak right about now. Wait, what was the question again?
upvoted 0 times
...
Glenn
1 months ago
I'm going with Port 110. What could be more innocent than good old POP3? The perfect disguise for a sneaky infection.
upvoted 0 times
Helene
10 days ago
User 3: Port 25 is often used for email communication, so it could be a potential choice for spreading malware.
upvoted 0 times
...
Kristeen
16 days ago
User 2: I'm going with Port 110 too, POP3 does seem innocent but can be used for malicious purposes.
upvoted 0 times
...
Jamie
27 days ago
User 1: I think it's Port 443, that's a common port for secure web traffic.
upvoted 0 times
...
...
Isaac
1 months ago
Port 443, really? That's way too obvious. Malware authors are usually more sophisticated than that.
upvoted 0 times
Lucina
16 days ago
D) Port 48101
upvoted 0 times
...
Elinore
18 days ago
Port 443 is commonly used for secure web traffic, but you're right, malware authors often try to be more sneaky.
upvoted 0 times
...
Buck
19 days ago
D) Port 48101
upvoted 0 times
...
Amira
20 days ago
C) Port 110
upvoted 0 times
...
Jesse
1 months ago
B) Port 443
upvoted 0 times
...
Coral
1 months ago
A) Port 25
upvoted 0 times
...
...
Lashandra
2 months ago
I agree with Coral, Port 443 is the correct answer because it's commonly used for HTTPS traffic.
upvoted 0 times
...
Coral
2 months ago
I'm leaning towards Port 443 as well, it's commonly used for secure communication.
upvoted 0 times
...
Eura
2 months ago
Hmm, I'm guessing Port 48101. That's a pretty obscure port, so it seems like something a sneaky malware would use.
upvoted 0 times
Eun
9 days ago
User 4: I'm going to go with Port 48101, it does seem sneaky.
upvoted 0 times
...
Mirta
22 days ago
User 3: I agree with Mirta, Port 443 sounds like a common choice for malware.
upvoted 0 times
...
Keva
24 days ago
User 2: I'm leaning towards Port 443.
upvoted 0 times
...
Gregoria
1 months ago
User 1: I think it might be Port 25.
upvoted 0 times
...
...
Stefanie
2 months ago
I disagree, I believe it's Port 443.
upvoted 0 times
...
Arlie
2 months ago
I think it's Port 25.
upvoted 0 times
...

Save Cancel