Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) — Question 8
An engineer receives a security alert that traffic with a known TOR exit node has occurred on the network.
What is the impact of this traffic?
Answer options
- A. ransomware communicating after infection
- B. users downloading copyrighted content
- C. data exfiltration
- D. user circumvention of the firewall
Correct answer: D
Explanation
The correct answer is D, as TOR is often used to bypass firewalls and maintain anonymity, indicating that users are evading network restrictions. Option A is incorrect because ransomware typically does not rely on TOR for communication post-infection. Option B is not necessarily true as downloading copyrighted content does not exclusively require TOR, and option C, while possible, does not directly relate to the primary purpose of using a TOR exit node.