Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is reviewing a NetFlow record that shows a large amount of data being transferred from an internal server to an external IP address on port 443 during non-business hours. Which type of activity should the analyst suspect?

⚠ Common exam trap

CS0-004 often tests the confusion between exfiltration and DoS — candidates see 'large amount of data' and think attack volume, but the direction (outbound to external IP) and timing (off-hours) are the discriminators for exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data exfiltration

Data exfiltration is correct because the pattern — a large volume of data transferred from an internal server to an external IP on port 443 during non-business hours — matches the classic signature of data exfiltration. Port 443 (HTTPS) is commonly used to blend in with normal encrypted web traffic, and off-hours timing plus high volume to an external destination indicates unauthorized data transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Denial-of-service attack

    Why it's wrong here

    A denial-of-service (DoS) attack typically manifests in NetFlow records as a massive volume of inbound traffic, such as SYN floods or UDP floods, directed at internal assets to exhaust resources. In contrast, this NetFlow record indicates a sustained, high-volume outbound data transfer to an external IP address. Because the traffic flow is predominantly outbound rather than inbound, a DoS attack is highly unlikely.

  • ✗

    Port scanning

    Why it's wrong here

    Port scanning behavior is characterized by a high frequency of short-lived connection attempts across a wide range of destination ports, often resulting in TCP RST or ICMP unreachable packets. NetFlow records for scanning show low byte counts per flow but a very high flow count. This record shows a single, persistent connection transferring a massive payload, which contradicts the signature of active reconnaissance.

  • ✗

    Normal backup operation

    Why it's wrong here

    While backup operations do involve large data transfers, legitimate enterprise backups are scheduled to target known internal storage area networks or authorized, encrypted cloud service endpoints. A massive outbound transfer to an unclassified, arbitrary external IP address over an unapproved encrypted channel violates standard backup baselines. This anomalous destination strongly suggests unauthorized activity rather than routine system maintenance.

  • ✓

    Data exfiltration

    Why this is correct

    Data exfiltration is characterized by an anomalous, large-volume outbound data transfer, often utilizing encrypted protocols like HTTPS or SFTP to bypass deep packet inspection. The NetFlow record's asymmetric flow pattern—showing minimal inbound bytes and a massive outbound payload to an external host—is a classic indicator of compromise. This signature points directly to an attacker successfully staging and extracting sensitive corporate data.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.