Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst is reviewing NetFlow records for a critical server. They observe a significant increase in outbound traffic to a single external IP address over a short period, with packets consistently having a size of 64 bytes. The destination port is non-standard and varies frequently. What type of attack pattern does this most strongly suggest?
- ADistributed Denial-of-Service (DDoS) attack
- BPort Scanning
- CData Exfiltration
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: C. Data Exfiltration
A significant increase in outbound traffic to a single external IP, especially with consistent small packet sizes and varied non-standard destination ports, is highly indicative of data exfiltration. Attackers often break data into small chunks and use varied ports to evade detection.
Why the other options are wrong
- A. DDoS attacks typically involve high inbound traffic from many sources, not high outbound to a single external IP.
- B. Port scanning involves attempts to connect to many ports on a target, usually with small inbound probes, not sustained outbound traffic.
- D. Brute-force attacks involve repeated login attempts, generating authentication failures, not large outbound data flows.
Data Exfiltration Indicators
Data exfiltration indicators are network or host-based signs that sensitive information is being illicitly transferred out of an organization's network.
- Unusually large outbound data transfers.
- Traffic to suspicious external IP addresses.
- Use of non-standard ports or protocols for data movement.
- Small, consistent packet sizes in outbound flows.
Memory trick: Intrusion indicators are like warning lights on your network dashboard.