Courseiva
Security Operations →mediumMultiple Select

CS0-003 Security Operations Practice Question

A security analyst is investigating a potential data exfiltration incident. The analyst observes the following network traffic from an internal host: Outbound connections to an external IP on port 22, large data transfers during off-hours, and the use of SCP. Which two indicators of compromise (IOCs) are most relevant? (Select TWO.)

⚠ Common exam trap

CS0-004 often tests the ability to distinguish between common network activities and specific IOCs of data exfiltration, such as SCP and off-hours large transfers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Large outbound data transfers during off-hours

Option C is correct because the scenario explicitly describes large data transfers occurring during off-hours, which is a classic exfiltration IOC indicating data is being moved out of the network when normal business activity and monitoring are minimal. Option D is correct because SCP operates over SSH on TCP port 22, and using SCP to an external IP is a concrete IOC showing a file-transfer protocol being abused to move data outbound, matching the observed port 22 traffic. The other options do not fit: frequent DNS queries (A) could suggest DNS tunneling but no such activity is described, HTTP POST requests (B) would indicate web-based exfiltration over ports 80/443 rather than SCP/22, and ICMP echo requests (E) are ordinary ping traffic and not consistent with the SCP-over-port-22 behavior observed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Frequent DNS queries

    Why it's wrong here

    Frequent DNS queries indicate domain generation algorithm beaconing or DNS tunnelling, not SCP over port 22. The stem's evidence is encrypted SSH file transfer, which produces no per-query DNS pattern. DNS monitoring is the right choice when exfiltration hides inside resolver traffic or malware resolves many algorithmically generated domains.

  • ✗

    HTTP POST requests

    Why it's wrong here

    HTTP POST requests carry web uploads on ports 80/443, whereas the observed SCP traffic runs inside SSH on port 22 with no HTTP layer. POST inspection is correct when exfiltration uses web forms, APIs or cloud storage endpoints rather than an SSH channel.

  • ✓

    Large outbound data transfers during off-hours

    Why this is correct

    Large outbound transfers during off-hours deviate from the host's normal baseline, indicating possible automated exfiltration rather than legitimate business activity. Volume combined with unusual timing is the behavioural anomaly that distinguishes data theft from routine traffic in this scenario.

  • ✓

    Use of SCP on port 22

    Why this is correct

    SCP over port 22 is a legitimate administrative protocol, so its presence alone is weak evidence. It becomes a relevant indicator only when correlated with the anomalous external destination and off-hours volume described in the stem, forming part of the exfiltration pattern.

  • ✗

    ICMP echo requests

    Why it's wrong here

    ICMP echo requests are small reachability probes, not bulk transfer; SCP moves file data inside an SSH session on port 22. ICMP analysis suits covert channels that tunnel payloads in echo request and reply fields, or reconnaissance sweeps mapping live hosts.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.