nerdexam
Cisco

350-201(NEW-127Q) · Question #12

Refer to the exhibit. An engineer is investigating several messages about undelivered emails and is reviewing cross-correlated data from different sources. It appears that the dates of returned…

The correct answer is C. data theft. Data theft (C) is correct because the scenario describes a classic data exfiltration pattern: an insider or attacker is copying large amounts of data to network shares and then attempting to email it out. The bounced/undelivered email notifications are a forensic trail - the…

Incident Response and Forensics

Question

Refer to the exhibit. An engineer is investigating several messages about undelivered emails and is reviewing cross-correlated data from different sources. It appears that the dates of returned undelivered emails match the dates of large data dumps on network shares. Which type of attack is occurring?

Options

  • Adata obfuscation
  • Bphishing
  • Cdata theft
  • Dsharming

How the community answered

(49 responses)
  • A
    16% (8)
  • B
    10% (5)
  • C
    69% (34)
  • D
    4% (2)

Explanation

Data theft (C) is correct because the scenario describes a classic data exfiltration pattern: an insider or attacker is copying large amounts of data to network shares and then attempting to email it out. The bounced/undelivered email notifications are a forensic trail - the dates correlate directly with the large data dumps, revealing that email was the intended exfiltration channel.

A (data obfuscation) is wrong because obfuscation means concealing or disguising data to make it unreadable, not stealing it - there's no indication here that data is being encoded or hidden. B (phishing) is wrong because phishing is an inbound social engineering attack used to trick users into surrendering credentials or clicking malicious links; this scenario shows outbound data movement. D (sharming) is a fabricated term and not a recognized attack category - it's a distractor designed to catch guessers.

Memory tip: Think "dump + email bounce = data theft caught in the act." When you see correlated evidence of large internal data movement and outbound email failures on the same dates, that timeline overlap is the signature of exfiltration via email.

Topics

#data exfiltration#incident correlation#attack detection#email forensics

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice