A security analyst notices that ACL deny logs show repeated hits from internal IP 192.168.1.50 attempting to reach an external malware C2 server. What is the most likely explanation?
-
A
The ACL is misconfigured and blocking legitimate traffic
-
B
The host 192.168.1.50 is infected and attempting to beacon out
-
C
The external server is performing a port scan
-
D
The ACL rule order is causing false positives