CompTIA CySA+ (CS0-003)Security OperationsMedium

A SOC analyst is investigating a suspected data exfiltration incident. Reviewing proxy logs, the analyst finds a significant volume of outbound traffic from an internal workstation to an external IP address (52.x.x.x) over port 443. The traffic size for each connection is small, but the connections are frequent and occur at irregular intervals. Further inspection of the traffic reveals a high degree of entropy in the data payloads. Which type of data exfiltration technique is most likely being employed?

  1. ADNS Query Exfiltration
  2. BHTTP/HTTPS Tunneling
  3. CFTP Data Transfer
  4. DSMB Share Copy
Show answer & explanation

Correct answer: B. HTTP/HTTPS Tunneling

Exfiltration over port 443 (HTTPS) with small, frequent, irregularly timed connections and high entropy data payloads strongly suggests HTTP/HTTPS tunneling. Attackers often use this method to blend in with legitimate web traffic, encrypt data, and bypass basic firewall rules and proxies. The high entropy indicates obfuscated or encrypted data, which is common in tunneling.

Why the other options are wrong

  • A. DNS query exfiltration involves encoding data within DNS queries and typically uses port 53, not 443. Also, the data size per query is usually very small, making 'significant volume' less likely to be solely DNS.
  • C. FTP (ports 20, 21) is typically blocked outbound by firewalls, and its traffic patterns for exfiltration would be different (larger, fewer connections).
  • D. SMB (ports 139, 445) is primarily an internal protocol and would rarely be used for direct outbound exfiltration to external IPs unless specific misconfigurations exist, and it would likely involve larger file transfers.

HTTP/HTTPS Tunneling

HTTP/HTTPS tunneling involves encapsulating other network protocols within HTTP or HTTPS requests/responses. This technique is often used by attackers to bypass firewalls and proxies for command and control or data exfiltration.

  • Uses common web ports (80, 443) to blend with legitimate traffic.
  • Encrypts data when using HTTPS, making content inspection difficult.
  • Can be detected by analyzing traffic patterns, payload entropy, and unusual HTTP headers.

Memory trick: Exfiltrating data is like smuggling secrets out in plain sight.

More Security Operations questions