CAS-004 Security Operations Practice Question
A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an insider is using encrypted tunnels to transfer data. Which TWO of the following network traffic analysis (NTA) indicators are most likely to suggest encrypted exfiltration? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Large data transfers to an external IP address during non-business hours
Unusual volumes of traffic to a single external IP, especially during off-hours, can indicate data exfiltration. Repeated connections to an external host using non-standard ports, even if encrypted, are suspicious because they may bypass security controls. DNS tunneling is detectable by high volumes of DNS queries to a single domain, but that is separate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Large data transfers to an external IP address during non-business hours
Why this is correct
Encrypted exfiltration often occurs outside business hours to avoid detection, and large transfers are a key indicator.
- ✗
Multiple HTTP GET requests to a known content delivery network
Why it's wrong here
This is normal traffic to a CDN, not indicative of exfiltration.
- ✗
A single large file upload to a cloud storage provider during work hours
Why it's wrong here
This could be legitimate business use, especially during work hours, and is less suspicious than off-hours transfers.
- ✓
Repeated connections to an external host on a non-standard port using TLS
Why this is correct
Using TLS on non-standard ports (e.g., 8443, 444) can indicate an attempt to hide exfiltration traffic.
- ✗
High volumes of DNS queries to a single external domain
Why it's wrong here
This indicates DNS tunneling, which is a form of exfiltration but is not necessarily encrypted; it uses DNS protocol. The question specifies encrypted tunnels.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.