CompTIA CySA+ (CS0-003)Security OperationsMedium
An analyst reviews NetFlow records for a 15-minute window and finds internal host 10.10.5.22 generated 4,500 flow records to external IP 203.0.113.55, totaling 3.6 GB sent and only 12 MB received. No other internal hosts communicate with this IP. What does this traffic pattern MOST likely indicate?
- AData exfiltration from the internal host to an external destination
- BNormal web browsing traffic to a CDN
- CA legitimate scheduled backup to a cloud storage provider
- DA DDoS reflection attack originating from the external host
Show answer & explanationAnswer & explanation
Correct answer: A. Data exfiltration from the internal host to an external destination
A 300:1 outbound-to-inbound byte ratio (3.6 GB out vs 12 MB in) sustained over many flows to a single unfamiliar external IP is a classic exfiltration signature, especially when no other hosts communicate with that destination.
Why the other options are wrong
- B. CDN browsing usually shows more balanced or inbound-heavy traffic (downloading content), not this heavy outbound skew.
- C. Legitimate backups are usually to known, whitelisted cloud endpoints and typically occur on a recognized schedule, which isn't confirmed here.
- D. A reflection attack would show traffic originating from many external sources toward a victim, not one internal host sending large volume outward.
NetFlow Exfiltration Indicator
NetFlow records showing a highly asymmetric outbound-to-inbound byte ratio from a single host to an unfamiliar external destination often indicate data exfiltration.
- NetFlow records src/dst IP, ports, bytes, packets, duration
- High outbound:inbound ratio to unknown IP = red flag
- Volume + destination rarity both matter for triage
Memory trick: 'Out way more than in, to somewhere unfamiliar' = data leaving the building.