Quiz 4 Question 4 of 20

An analyst reviews firewall logs and notices that a web server in the DMZ initiated an outbound connection to an external IP on port 4444. The DMZ firewall policy only allows inbound connections to the web server. What does this event most likely indicate, and what log source should be examined next?

Select an answer to reveal the explanation.

Motivation