Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is investigating a suspected data exfiltration incident. They are reviewing NetFlow records for a server in the DMZ that unexpectedly communicated with a foreign IP address for an extended period. The NetFlow records show a single, long-duration flow with a very high byte count transmitted from the internal server to the external IP, primarily using TCP port 443. What is the most likely exfiltration technique being used?

  1. APort scanning
  2. BEncrypted tunnel over HTTPS
  3. CICMP tunneling
  4. DDNS tunneling
Show answer & explanation

Correct answer: B. Encrypted tunnel over HTTPS

A single, long-duration flow with a high byte count over TCP port 443 strongly indicates data exfiltration using an encrypted tunnel, such as HTTPS, to blend in with legitimate web traffic.

Why the other options are wrong

  • A. Port scanning involves many connection attempts to different ports, not a single long-duration flow with high byte count.
  • C. ICMP tunneling uses ICMP echo requests/replies, not TCP port 443, and usually involves smaller data chunks.
  • D. DNS tunneling typically involves many small DNS queries and responses, not a single long flow with high byte count.

Encrypted Tunnel Exfiltration

This technique involves encapsulating stolen data within an encrypted communication channel, often using common protocols like HTTPS (TCP 443) or SSH, to bypass firewalls and evade detection.

  • Uses legitimate-looking ports (e.g., 443, 22)
  • Data is encrypted, making content inspection difficult
  • Often characterized by long-duration flows and high byte counts
  • Aims to blend in with normal network traffic

Memory trick: Exfiltrate data like a 'Stealthy Stream' by blending in with normal traffic flows.

More Network Intrusion Analysis questions