โ† All ACL Flashcard Decks

Threat Intelligence & Analysis Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Threat Intelligence & Analysis flashcards as text
  1. An ACL log shows repeated permit hits on port 443 from a single external IP at 3-second intervals over 6 hours. What threat does this most likely indicate?

    Answer: Automated beacon or C2 check-in traffic

    Regular, timed connections from a single host are a hallmark of malware beaconing to a command-and-control server.

  2. Which threat intelligence feed format is most commonly used to share ACL-relevant indicators such as malicious IP ranges and domain lists in a machine-readable way?

    Answer: STIX/TAXII

    STIX defines the structured format for threat indicators, and TAXII is the transport protocol used to share them automatically.

  3. A threat analyst wants to add ACL deny rules based on IPs listed in a threat intelligence feed. What risk must be evaluated before applying the rules to a production router?

    Answer: False positives blocking legitimate business traffic

    Threat feeds can contain inaccurate or outdated entries that may match legitimate IP addresses, causing unintended traffic drops.

  4. In ACL threat analysis, what does a 'deny any any' log entry at the end of an ACL reveal about network activity?

    Answer: Traffic that matched no earlier permit rule hit the implicit deny

    The implicit or explicit 'deny any any' at the end catches and logs all traffic that did not match any preceding permit statement.

  5. Which type of threat actor is most likely to conduct slow, low-volume port scans that attempt to evade ACL-based detection?

    Answer: Advanced Persistent Threat (APT) actors

    APT actors deliberately use slow, distributed scanning techniques to avoid triggering rate-based ACL logging thresholds.

  6. An analyst reviews ACL logs and notices permit hits on TCP port 4444 to an internal server from an external IP. What threat is most associated with this port?

    Answer: Metasploit default reverse shell listener

    TCP port 4444 is the default listener port for Metasploit reverse shells and is commonly associated with post-exploitation activity.

  7. What is the primary purpose of analyzing ACL hit counts over time when performing threat intelligence analysis?

    Answer: To identify traffic baseline deviations that may indicate attacks

    Comparing current hit counts against established baselines helps analysts detect anomalous spikes that may indicate scanning, flooding, or exfiltration attempts.