Identifying Backdoors from External Network Traffic
A user downloaded software from an online forum. After the user installed the software, the security team observed external network traffic connecting to the user's computer on an uncommon port. Which of the following is the most likely explanation of this unauthorized connection?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core trap is distinguishing between data exfiltration (keylogger) and persistent access (backdoor); unusual inbound traffic specifically points to a backdoor.
This question tests the ability to identify malware types based on post-installation network behavior. The correct answer is D, as external connections on uncommon ports indicate a backdoor facilitating unauthorized remote access.
Candidates often choose A (Keylogger) because it involves sending data out, but keyloggers typically initiate outbound connections to send stolen data rather than accepting incoming control connections.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A backdoor is a method bypassing normal authentication to gain remote access to a system. When software downloaded from an untrusted source contains a backdoor, it often opens a listening port or initiates a connection to a Command and Control (C2) server. The observation of "external network traffic connecting to the user's computer" implies an inbound connection attempt or an established session initiated by the malware to allow attacker control, which is the defining characteristic of a backdoor.Why the Other Options Are Wrong
Option A (Keylogger) primarily focuses on capturing input; while it sends data out, it does not typically establish a persistent inbound channel for remote control. Option B (Ransomware) is designed to encrypt files locally and demand payment, not to maintain a remote administrative shell. Option C (Fileless virus) refers to malware that runs in memory without writing to disk; while possible, the explicit mention of downloading and installing specific software makes a traditional infected executable with a backdoor the most direct explanation for the observed connectivity.Community Comment Notes
The community consensus strongly supports D, with users noting that backdoors are specifically designed to enable unauthorized remote access. One commenter highlighted that while keyloggers might use uncommon ports, they don't provide the same level of remote control evidence as a backdoor. Another user emphasized that ransomware encrypts files rather than connecting externally for control purposes.Exam Strategy
When analyzing malware symptoms, look for the purpose of the network activity: 'sending data out' suggests spyware/keyloggers, while 'accepting connections' or 'remote control' suggests backdoors or RATs (Remote Access Trojans). Always prioritize the primary function described in the scenario.
Frequently Asked Questions
Why isn't this a keylogger if it uses an uncommon port?
Keyloggers typically send data outbound to a collector. An inbound connection or a persistent channel for remote control is characteristic of a backdoor.
Could fileless malware cause this?
Fileless malware operates in memory, but the scenario specifies downloading and installing software, making a standard infected executable with a backdoor the more likely root cause.