nerdexam
Splunk

SPLK-5001 · Question #67

An analyst notices that one of their servers is sending an unusually large amount of traffic, gigabytes more than normal, to a single system on the Internet. There doesn't seem to be any associated…

The correct answer is A. Data exfiltration. Data exfiltration (A) fits perfectly: a server quietly sending gigabytes outbound to a single external destination - with no corresponding inbound spike - is the classic signature of stolen data being siphoned out. Attackers often avoid triggering inbound alerts by keeping the…

Threat Detection and Alerting

Question

An analyst notices that one of their servers is sending an unusually large amount of traffic, gigabytes more than normal, to a single system on the Internet. There doesn't seem to be any associated increase in incoming traffic. What type of threat actor activity might this represent?

Options

  • AData exfiltration
  • BNetwork reconnaissance
  • CData infiltration
  • DLateral movement

How the community answered

(34 responses)
  • A
    76% (26)
  • B
    12% (4)
  • C
    6% (2)
  • D
    6% (2)

Explanation

Data exfiltration (A) fits perfectly: a server quietly sending gigabytes outbound to a single external destination - with no corresponding inbound spike - is the classic signature of stolen data being siphoned out. Attackers often avoid triggering inbound alerts by keeping the data flow one-directional.

B (Network reconnaissance) is wrong because reconnaissance involves scanning and probing targets to map a network, which generates small packets in many directions - not sustained, high-volume outbound transfers.

C (Data infiltration) is the reverse scenario: an attacker pushing large amounts of data into your environment (e.g., dropping malware or tools). The question describes outbound traffic, not inbound.

D (Lateral movement) is wrong because lateral movement happens inside a network - an attacker pivoting between internal systems - not sending traffic to a single external internet destination.

Memory tip: Think of the prefix: exfiltration = data exiting your network. If traffic is leaving unexpectedly in bulk, the data is being extracted. "Exfil = exit."

Topics

#data exfiltration#network traffic analysis#anomalous behavior#threat identification

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice