nerdexam
CompTIA

SY0-701 · Question #401

A security analyst received a tip that sensitive proprietary information was leaked to the public. The analyst is reviewing the PCAP and notices traffic between an internal server and an external host

Sign in or unlock SY0-701 to reveal the answer and full explanation for question #401. The question stem and answer options stay visible for context.

Submitted by akirajp· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

A security analyst received a tip that sensitive proprietary information was leaked to the public. The analyst is reviewing the PCAP and notices traffic between an internal server and an external host that includes the following:

... 12:47:22.327233 PPPoE [ses 0x8122] IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto IPv6 (41), length 331) 10.5.1.1 > 52.165.16.154: IP6 (hlim E3, next-header TCP (6) paylcad length: 271) 2001:67c:2158:a019::ace.53104 > 2001:0:5ef5:79fd:380c:dddd:a601:24fa.13788: Flags [P.], cksum 0xd7ee (correct), seq 97:348, ack 102, win 16444, length 251 ... Which of the following was most likely used to exfiltrate the data?

Options

  • AEncapsulation
  • BMAC address spoofing
  • CSteganography
  • DBroken encryption
  • ESniffing via on-path position

Unlock SY0-701 to see the answer

You've previewed enough free SY0-701 questions. Unlock SY0-701 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SY0-701 Practice