CompTIA Security+ (SY0-701)Security OperationsEasy
A security analyst is investigating a suspected data exfiltration event. The analyst discovers large volumes of encrypted traffic originating from an internal server to an unknown external IP address during off-peak hours. Which of the following is the MOST likely indicator of compromise (IOC)?
- AHigh CPU utilization on the internal server
- BNew user accounts created on the internal server
- CFailed login attempts on the internal server
- DUnusual outbound encrypted traffic patterns
Show answer & explanationAnswer & explanation
Correct answer: D. Unusual outbound encrypted traffic patterns
Unusual outbound encrypted traffic, especially large volumes during off-peak hours to an unknown destination, is a strong indicator of potential data exfiltration. Attackers often encrypt exfiltrated data to evade detection.
Why the other options are wrong
- A. High CPU utilization could indicate many things, including legitimate processes, and is not as specific to data exfiltration.
- B. New user accounts could indicate a compromise, but unusual traffic patterns are more directly linked to the act of data exfiltration itself.
- C. Failed login attempts are indicative of brute-force attacks or credential stuffing, not directly data exfiltration.
Indicator of Compromise (IOC)
An artifact observed on a network or in an operating system that reliably indicates a computer intrusion.
- Evidence of a breach
- Can be network or host-based
- Used for detection and incident response
Memory trick: IOCs are like crime scene clues, pointing to a breach.