nerdexam
Cisco

200-201 · Question #546

An engineer is examining a particular network traffic sample from multiple sources aggregated into an alert via the company SIEM. These observations are noted within said alert: an increase in…

The correct answer is A. A security breach is occurring that involves potential data exfiltration through unauthorized and. The combination of off-hours traffic spikes, suspicious admin logins from multiple locations, encrypted file transfers to a blacklisted domain, and DLP alerts indicates active data exfiltration as part of a security breach.

Submitted by carlos_mx· Mar 6, 2026Security Monitoring

Question

An engineer is examining a particular network traffic sample from multiple sources aggregated into an alert via the company SIEM. These observations are noted within said alert: an increase in outbound traffic volume at 2 AM, multiple admin account sign-ins from geographically disparate locations, a series of encrypted file uploads to a recently blacklisted domain, and alert triggers from the DLP for unauthorized file types. What is occurring?

Options

  • AA security breach is occurring that involves potential data exfiltration through unauthorized and
  • BAn administrator is conducting system updates and testing encryption protocols during off hours.
  • CEmployees from global offices are collaborating on a project that requires extensive file sharing
  • DDisaster recovery plans are being activated, involving data replication to an offsite location for

How the community answered

(20 responses)
  • A
    45% (9)
  • B
    10% (2)
  • C
    15% (3)
  • D
    30% (6)

Explanation

The combination of off-hours traffic spikes, suspicious admin logins from multiple locations, encrypted file transfers to a blacklisted domain, and DLP alerts indicates active data exfiltration as part of a security breach.

Topics

#SIEM analysis#data exfiltration#incident detection#DLP alerts

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice