CompTIA Security+ (SY0-701)Security OperationsEasy

A security analyst is investigating a suspected data exfiltration event. The analyst discovers large volumes of encrypted traffic originating from an internal server to an unknown external IP address during off-peak hours. Which of the following is the MOST likely indicator of compromise (IOC)?

  1. AHigh CPU utilization on the internal server
  2. BNew user accounts created on the internal server
  3. CFailed login attempts on the internal server
  4. DUnusual outbound encrypted traffic patterns
Show answer & explanation

Correct answer: D. Unusual outbound encrypted traffic patterns

Unusual outbound encrypted traffic, especially large volumes during off-peak hours to an unknown destination, is a strong indicator of potential data exfiltration. Attackers often encrypt exfiltrated data to evade detection.

Why the other options are wrong

  • A. High CPU utilization could indicate many things, including legitimate processes, and is not as specific to data exfiltration.
  • B. New user accounts could indicate a compromise, but unusual traffic patterns are more directly linked to the act of data exfiltration itself.
  • C. Failed login attempts are indicative of brute-force attacks or credential stuffing, not directly data exfiltration.

Indicator of Compromise (IOC)

An artifact observed on a network or in an operating system that reliably indicates a computer intrusion.

  • Evidence of a breach
  • Can be network or host-based
  • Used for detection and incident response

Memory trick: IOCs are like crime scene clues, pointing to a breach.

More Security Operations questions