CS0-003 Security Operations Practice Question
A security analyst is investigating a potential data exfiltration incident. The analyst observes the following network traffic from an internal host: Outbound connections to an external IP on port 22, large data transfers during off-hours, and the use of SCP. Which two indicators of compromise (IOCs) are most relevant? (Select TWO.)
⚠ Common exam trap
CS0-004 often tests the ability to distinguish between common network activities and specific IOCs of data exfiltration, such as SCP and off-hours large transfers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Large outbound data transfers during off-hours
Option C is correct because the scenario explicitly describes large data transfers occurring during off-hours, which is a classic exfiltration IOC indicating data is being moved out of the network when normal business activity and monitoring are minimal. Option D is correct because SCP operates over SSH on TCP port 22, and using SCP to an external IP is a concrete IOC showing a file-transfer protocol being abused to move data outbound, matching the observed port 22 traffic. The other options do not fit: frequent DNS queries (A) could suggest DNS tunneling but no such activity is described, HTTP POST requests (B) would indicate web-based exfiltration over ports 80/443 rather than SCP/22, and ICMP echo requests (E) are ordinary ping traffic and not consistent with the SCP-over-port-22 behavior observed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Frequent DNS queries
Why it's wrong here
Frequent DNS queries indicate domain generation algorithm beaconing or DNS tunnelling, not SCP over port 22. The stem's evidence is encrypted SSH file transfer, which produces no per-query DNS pattern. DNS monitoring is the right choice when exfiltration hides inside resolver traffic or malware resolves many algorithmically generated domains.
- ✗
HTTP POST requests
Why it's wrong here
HTTP POST requests carry web uploads on ports 80/443, whereas the observed SCP traffic runs inside SSH on port 22 with no HTTP layer. POST inspection is correct when exfiltration uses web forms, APIs or cloud storage endpoints rather than an SSH channel.
- ✓
Large outbound data transfers during off-hours
Why this is correct
Large outbound transfers during off-hours deviate from the host's normal baseline, indicating possible automated exfiltration rather than legitimate business activity. Volume combined with unusual timing is the behavioural anomaly that distinguishes data theft from routine traffic in this scenario.
- ✓
Use of SCP on port 22
Why this is correct
SCP over port 22 is a legitimate administrative protocol, so its presence alone is weak evidence. It becomes a relevant indicator only when correlated with the anomalous external destination and off-hours volume described in the stem, forming part of the exfiltration pattern.
- ✗
ICMP echo requests
Why it's wrong here
ICMP echo requests are small reachability probes, not bulk transfer; SCP moves file data inside an SSH session on port 22. ICMP analysis suits covert channels that tunnel payloads in echo request and reply fields, or reconnaissance sweeps mapping live hosts.
Go deeper
Related to this question
Learn chapter
Network Traffic Analysis
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
IOC
IOC stands for Indicator of Compromise, which is forensic evidence that a system has been breached or infected by malware.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.