Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is investigating a potential data exfiltration incident. Network logs show a large volume of outbound traffic from an internal database server to an unfamiliar external IP address over port 443. The traffic occurs daily at 02:00 and lasts for exactly 15 minutes. The analyst suspects the use of a covert channel. Which of the following techniques is the analyst MOST likely observing?

⚠ Common exam trap

The trap here is focusing on the term 'covert channel' and jumping to DNS tunneling or ICMP, when the port and traffic pattern clearly indicate HTTPS-based exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled data transfer using a covert channel over HTTPS

The combination of HTTPS (port 443), a fixed daily schedule, and a consistent short duration strongly suggests an automated exfiltration script using a covert channel that mimics legitimate web traffic. This method allows data to leave the network without raising alarms based on port or protocol anomalies. The unfamiliar external IP and the database server as the source further point to a compromised host exfiltrating data via an encrypted channel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scheduled data transfer using a covert channel over HTTPS

    Why this is correct

    The traffic is outbound on port 443 (HTTPS), occurs at a fixed time daily, and lasts a consistent duration. This pattern suggests an automated, scheduled exfiltration using a covert channel that blends with normal HTTPS traffic. The use of port 443 helps evade detection that focuses on non-standard ports, and the regularity indicates a scripted task rather than interactive user activity.

  • ✗

    DNS tunneling

    Why it's wrong here

    DNS tunneling encodes data in DNS queries and responses, typically using port 53. The traffic here is on port 443, which is HTTPS. Although DNS tunneling can be used for exfiltration, it would not generate large volumes of HTTPS traffic to a single external IP. The port and traffic pattern do not match DNS tunneling.

  • ✗

    ICMP exfiltration

    Why it's wrong here

    ICMP exfiltration would use ICMP echo requests/replies to carry data, not TCP port 443. The scenario specifies outbound traffic over port 443, which is TCP-based HTTPS. ICMP traffic would not be described as on port 443, and its volume and timing patterns would differ. Thus, this is not the observed technique.

  • ✗

    Domain fronting

    Why it's wrong here

    Domain fronting uses different domain names in the TLS SNI and HTTP Host headers to hide the true destination, often leveraging CDNs. While it can disguise traffic, it typically involves connections to legitimate CDN IPs, not an unfamiliar external IP. The scenario describes consistent direct connections to a specific unknown IP, which is more indicative of a scheduled covert channel than domain fronting.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.