Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is reviewing NetFlow records for a critical server. They observe a significant increase in outbound traffic to a single external IP address over a short period, with packets consistently having a size of 64 bytes. The destination port is non-standard and varies frequently. What type of attack pattern does this most strongly suggest?

  1. ADistributed Denial-of-Service (DDoS) attack
  2. BPort Scanning
  3. CData Exfiltration
  4. DBrute-force attack
Show answer & explanation

Correct answer: C. Data Exfiltration

A significant increase in outbound traffic to a single external IP, especially with consistent small packet sizes and varied non-standard destination ports, is highly indicative of data exfiltration. Attackers often break data into small chunks and use varied ports to evade detection.

Why the other options are wrong

  • A. DDoS attacks typically involve high inbound traffic from many sources, not high outbound to a single external IP.
  • B. Port scanning involves attempts to connect to many ports on a target, usually with small inbound probes, not sustained outbound traffic.
  • D. Brute-force attacks involve repeated login attempts, generating authentication failures, not large outbound data flows.

Data Exfiltration Indicators

Data exfiltration indicators are network or host-based signs that sensitive information is being illicitly transferred out of an organization's network.

  • Unusually large outbound data transfers.
  • Traffic to suspicious external IP addresses.
  • Use of non-standard ports or protocols for data movement.
  • Small, consistent packet sizes in outbound flows.

Memory trick: Intrusion indicators are like warning lights on your network dashboard.

More Security Monitoring questions