hardMultiple Select
CS0-003 Practice Question: A threat hunter suspects data exfiltration over…
A threat hunter suspects data exfiltration over HTTPS from a database server. Which data sources are most useful? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that encrypted traffic (HTTPS) is completely opaque, leading candidates to overlook metadata sources like NetFlow or proxy logs that can reveal exfiltration patterns without decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Database audit logs showing queried objects and accounts
Database audit logs record which objects (tables, columns) were queried and by which accounts, directly revealing unauthorized access or unusual data retrieval patterns that could indicate exfiltration. NetFlow or proxy logs capture destination IP addresses, data volumes, and timing of HTTPS sessions, allowing the hunter to spot large or anomalous outbound transfers to suspicious hosts, even though the payload is encrypted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Database audit logs showing queried objects and accounts
Why this is correct
Database audit logs are critical for identifying data exfiltration because they record specific queries executed, the objects (tables, columns) accessed, and the user accounts performing these actions. These logs can reveal unauthorized access to sensitive data, unusual query patterns, or the bulk retrieval of information just prior to suspected exfiltration, directly linking internal data manipulation to potential outbound transfers. This provides crucial evidence of *what* data was accessed and *who* accessed it.
- ✗
Printer toner status
Why it's wrong here
Printer toner status logs provide operational information about the supply levels of a printing device. While important for IT asset management and maintenance, these logs offer no insight into network traffic patterns, data access, or outbound data transfers, making them entirely irrelevant for detecting or investigating data exfiltration, especially over HTTPS. They monitor a physical consumable, not logical data movement.
- ✗
Building temperature logs
Why it's wrong here
Building temperature logs record environmental conditions within a facility, such as server room temperatures or HVAC performance. These logs are primarily used for physical infrastructure monitoring and environmental control, ensuring optimal operating conditions for hardware. They contain no information related to network activity, data flow, user actions, or system processes, rendering them completely useless for detecting or understanding data exfiltration attempts.
- ✓
NetFlow or proxy logs showing destination, volume, and timing
Why this is correct
NetFlow or proxy logs are invaluable for detecting data exfiltration as they provide essential network metadata without necessarily decrypting the content. These logs detail the destination IP addresses, the volume of data transferred, and the precise timing of connections, allowing threat hunters to identify unusual outbound traffic patterns, connections to suspicious external hosts, or abnormally large data transfers that are indicative of exfiltration. This network-level visibility helps establish the "how" and "where" of the transfer.
Go deeper
Related to this question
Learn chapter
Packet Capture: Wireshark and tcpdump
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.