CAS-004 Security Operations Practice Question
A security analyst is investigating a potential data exfiltration incident. Network logs show a large volume of outbound traffic from an internal database server to an unfamiliar external IP address over port 443. The traffic occurs daily at 02:00 and lasts for exactly 15 minutes. The analyst suspects the use of a covert channel. Which of the following techniques is the analyst MOST likely observing?
⚠ Common exam trap
The trap here is focusing on the term 'covert channel' and jumping to DNS tunneling or ICMP, when the port and traffic pattern clearly indicate HTTPS-based exfiltration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scheduled data transfer using a covert channel over HTTPS
The combination of HTTPS (port 443), a fixed daily schedule, and a consistent short duration strongly suggests an automated exfiltration script using a covert channel that mimics legitimate web traffic. This method allows data to leave the network without raising alarms based on port or protocol anomalies. The unfamiliar external IP and the database server as the source further point to a compromised host exfiltrating data via an encrypted channel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Scheduled data transfer using a covert channel over HTTPS
Why this is correct
The traffic is outbound on port 443 (HTTPS), occurs at a fixed time daily, and lasts a consistent duration. This pattern suggests an automated, scheduled exfiltration using a covert channel that blends with normal HTTPS traffic. The use of port 443 helps evade detection that focuses on non-standard ports, and the regularity indicates a scripted task rather than interactive user activity.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling encodes data in DNS queries and responses, typically using port 53. The traffic here is on port 443, which is HTTPS. Although DNS tunneling can be used for exfiltration, it would not generate large volumes of HTTPS traffic to a single external IP. The port and traffic pattern do not match DNS tunneling.
- ✗
ICMP exfiltration
Why it's wrong here
ICMP exfiltration would use ICMP echo requests/replies to carry data, not TCP port 443. The scenario specifies outbound traffic over port 443, which is TCP-based HTTPS. ICMP traffic would not be described as on port 443, and its volume and timing patterns would differ. Thus, this is not the observed technique.
- ✗
Domain fronting
Why it's wrong here
Domain fronting uses different domain names in the TLS SNI and HTTP Host headers to hide the true destination, often leveraging CDNs. While it can disguise traffic, it typically involves connections to legitimate CDN IPs, not an unfamiliar external IP. The scenario describes consistent direct connections to a specific unknown IP, which is more indicative of a scheduled covert channel than domain fronting.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.