CompTIA CySA+ (CS0-003)Reporting and CommunicationHard
A security analyst is investigating a suspected data exfiltration event. The analyst reviews firewall logs and identifies suspicious outbound connections to an unknown IP address (185.220.101.11) on port 443 from an internal server. The analyst needs to include relevant log snippets in the incident report. Which of the following log entries would be MOST indicative of data exfiltration?
- A2023-11-01 10:03:30 FW_LOG OUTBOUND ICMP 192.168.1.1:PING -> 8.8.8.8:PING ALLOWED (Network connectivity test)
- B2023-11-01 10:02:20 FW_LOG INBOUND UDP 203.0.113.1:53 -> 192.168.1.100:53 ALLOWED (DNS query)
- C2023-11-01 10:01:15 FW_LOG OUTBOUND TCP 172.16.0.20:54321 -> 185.220.101.11:443 BYTES_SENT=50000000 ALLOWED (Large data transfer detected)
- D2023-11-01 10:00:05 FW_LOG INITIATE TCP 192.168.1.10:80 -> 10.0.0.5:443 ALLOWED (Web server communicating internally)
Show answer & explanationAnswer & explanation
Correct answer: C. 2023-11-01 10:01:15 FW_LOG OUTBOUND TCP 172.16.0.20:54321 -> 185.220.101.11:443 BYTES_SENT=50000000 ALLOWED (Large data transfer detected)
Data exfiltration is characterized by unauthorized outbound transfer of large volumes of data. Option B shows an 'OUTBOUND' connection from an internal IP to an unknown external IP on port 443, critically, with a 'BYTES_SENT=50000000' (50 MB) indicator, which is a strong sign of a large data transfer, highly indicative of exfiltration.
Why the other options are wrong
- A. This is a small outbound ICMP packet for a connectivity test, not a large data transfer associated with exfiltration.
- B. This is an inbound DNS query, a normal network activity, not outbound data transfer.
- D. This is an internal communication, not outbound to an unknown external IP, and doesn't indicate large data transfer.
Data Exfiltration Indicators
Specific patterns or anomalies in network traffic, logs, or system behavior that suggest unauthorized transfer of data out of an organization's network.
- Large outbound data transfers.
- Connections to unknown or suspicious external IP addresses.
- Use of unusual protocols or ports for data transfer.
- Activity outside normal business hours.
Memory trick: Exfiltration logs: look for OUTBOUND, UNKNOWN, and BIG data.