Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringHard

A security analyst is investigating a potential data exfiltration incident. Network traffic analysis reveals large volumes of encrypted data being sent from an internal server to an external IP address over an unusual port (TCP 53000). The internal server's legitimate function does not involve outbound connections of this nature. Which network intrusion analysis technique is most critical for determining the content of the exfiltrated data?

  1. APacket capture and decryption (if possible) to inspect payload.
  2. BNetFlow analysis to identify source and destination IPs.
  3. CFirewall log review to confirm blocked connections.
  4. DDNS query analysis to detect command and control (C2) channels.
Show answer & explanation

Correct answer: A. Packet capture and decryption (if possible) to inspect payload.

To determine the *content* of exfiltrated data, direct inspection of the data itself is required. Since the data is encrypted, the most critical step is to obtain a packet capture and then attempt decryption using available keys or certificates. Other options identify traffic but don't reveal content.

Why the other options are wrong

  • B. NetFlow identifies 'who talked to whom, when, and how much,' but not 'what' was said (content).
  • C. Firewall logs confirm connection attempts/blocks, not the content of successful outbound traffic.
  • D. DNS analysis helps identify C2, but not the content of data exfiltrated via another channel.

Packet Capture & Decryption

The process of intercepting and recording network traffic (packet capture) and subsequently converting encrypted traffic back into readable plaintext (decryption) to analyze its contents.

  • Essential for deep inspection of network payload data.
  • Requires access to encryption keys/certificates for encrypted traffic.
  • Tools like Wireshark are used for capture and analysis.

Memory trick: To know what's in the box, you need the key, or at least a peek!

More Security Monitoring questions