CS0-003 · Question #350
A security analyst observed the following activities in chronological order: 1. Protocol violation alerts on external firewall 2. Unauthorized internal scanning activity 3. Changes in outbound…
The correct answer is A. Data exfiltration. The observed sequence of events-firewall alerts, internal scanning, and changes in outbound network performance-strongly indicates that an attacker has compromised a system and is attempting to steal data from the network.
Question
Options
- AData exfiltration
- BUnusual traffic spikes
- CRogue devices
- DIrregular peer-to-peer communication
How the community answered
(51 responses)- A63% (32)
- B10% (5)
- C6% (3)
- D22% (11)
Why each option
The observed sequence of events-firewall alerts, internal scanning, and changes in outbound network performance-strongly indicates that an attacker has compromised a system and is attempting to steal data from the network.
Data exfiltration involves unauthorized transfer of data out of a network. Protocol violation alerts and internal scanning suggest initial compromise and reconnaissance, while changes in outbound network performance (e.g., increased traffic) are a common indicator of large volumes of data being sent externally, consistent with data theft.
While data exfiltration can cause unusual traffic spikes, 'Unusual traffic spikes' is a symptom, not the ultimate goal of a threat actor in this context; data exfiltration describes the attacker's objective.
Rogue devices might be used for compromise or data theft, but the observed activities (protocol violations, scanning, outbound performance changes) directly point to data movement rather than just the presence of an unauthorized device.
Irregular peer-to-peer communication might occur, but it is too specific and does not encompass the broader implications of protocol violations, internal scanning, and significant outbound network performance changes that suggest a goal of data theft.
Concept tested: Identifying attacker goals based on attack progression
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-365/data-exfiltration?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.