Quiz 2 Question 14 of 20

An EDR alert shows workstation-17 opening TCP connections to ports 22, 80, 135, 445, and 3389 on 42 internal servers between 02:10 and 02:18. The SIEM has no change ticket, the source is a standard user laptop, and the process tree includes cmd.exe spawning net.exe. Which finding most strongly indicates malicious reconnaissance rather than benign network administration?

Select an answer to reveal the explanation.

Motivation