nerdexam
CompTIA

CS0-003 · Question #350

A security analyst observed the following activities in chronological order: 1. Protocol violation alerts on external firewall 2. Unauthorized internal scanning activity 3. Changes in outbound…

The correct answer is A. Data exfiltration. The observed sequence of events-firewall alerts, internal scanning, and changes in outbound network performance-strongly indicates that an attacker has compromised a system and is attempting to steal data from the network.

Submitted by anna_se· Mar 6, 2026Security operations

Question

A security analyst observed the following activities in chronological order: 1. Protocol violation alerts on external firewall 2. Unauthorized internal scanning activity 3. Changes in outbound network performance Which of the following best describes the goal of the threat actor?

Options

  • AData exfiltration
  • BUnusual traffic spikes
  • CRogue devices
  • DIrregular peer-to-peer communication

How the community answered

(51 responses)
  • A
    63% (32)
  • B
    10% (5)
  • C
    6% (3)
  • D
    22% (11)

Why each option

The observed sequence of events-firewall alerts, internal scanning, and changes in outbound network performance-strongly indicates that an attacker has compromised a system and is attempting to steal data from the network.

AData exfiltrationCorrect

Data exfiltration involves unauthorized transfer of data out of a network. Protocol violation alerts and internal scanning suggest initial compromise and reconnaissance, while changes in outbound network performance (e.g., increased traffic) are a common indicator of large volumes of data being sent externally, consistent with data theft.

BUnusual traffic spikes

While data exfiltration can cause unusual traffic spikes, 'Unusual traffic spikes' is a symptom, not the ultimate goal of a threat actor in this context; data exfiltration describes the attacker's objective.

CRogue devices

Rogue devices might be used for compromise or data theft, but the observed activities (protocol violations, scanning, outbound performance changes) directly point to data movement rather than just the presence of an unauthorized device.

DIrregular peer-to-peer communication

Irregular peer-to-peer communication might occur, but it is too specific and does not encompass the broader implications of protocol violations, internal scanning, and significant outbound network performance changes that suggest a goal of data theft.

Concept tested: Identifying attacker goals based on attack progression

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-365/data-exfiltration?view=o365-worldwide

Topics

#Data exfiltration#network anomalies#threat actor goals

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice