Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is investigating a potential data exfiltration incident. The analyst observes that a large amount of data is being transferred from an internal database server to an external IP address during non-business hours. The transfer is using an encrypted channel that is not typical for the server's normal operations. Which type of threat is this activity most likely associated with?

⚠ Common exam trap

The trap here is assuming that any data transfer is ransomware or DDoS, but the stealthy, encrypted exfiltration during off-hours points to a persistent threat actor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Advanced persistent threat (APT)

An advanced persistent threat is a prolonged and targeted attack where an intruder gains access to a network and remains undetected to steal data. The scenario's characteristics—large data transfer to an external IP, encrypted channel, and non-business hours—are typical of APT exfiltration. DDoS, ransomware, and phishing do not match the observed behavior of stealthy outbound data transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Advanced persistent threat (APT)

    Why this is correct

    An advanced persistent threat often involves stealthy, prolonged access to a network to steal data over time. The scenario describes data exfiltration using an encrypted channel during non-business hours, which aligns with APT tactics. APTs aim to maintain persistence and exfiltrate sensitive information without detection, making this the most likely threat type.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering attack that tricks users into revealing credentials or clicking malicious links. While phishing can be an initial access vector for an APT, the scenario describes an ongoing data transfer, not the initial deception. Phishing itself does not directly cause large-scale data exfiltration from a database server.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware encrypts files and demands payment for decryption, typically causing immediate disruption. In this scenario, there is no mention of file encryption or ransom notes; instead, data is being transferred out. Ransomware does not usually involve stealthy exfiltration of large data volumes, so it is not the most likely threat.

  • ✗

    Distributed denial of service (DDoS)

    Why it's wrong here

    A DDoS attack aims to overwhelm a system or network with traffic to make it unavailable, not to transfer data out. In this scenario, the activity involves data leaving the organization, which is characteristic of exfiltration, not a denial of service. DDoS would typically show a flood of inbound traffic, not outbound data transfers.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.