A threat hunter analyzes NetFlow data and observes a host communicating with multiple external IP addresses on high-numbered ports (e.g., 49300-49500) during off-hours. The communications are short-lived and occur in burst patterns. The hunter suspects data exfiltration. Which of the following analysis techniques would best confirm or refute this suspicion?
Performing a full packet capture (PCAP) is the most effective action because it allows the analyst to conduct deep packet inspection on the suspicious traffic. By analyzing the actual payloads and protocol headers, the threat hunter can definitively determine if sensitive data is being exfiltrated or if the traffic is benign. This provides the granular visibility that high-level NetFlow metadata lacks, confirming the exact nature of the transmission.
Why this answer
A full packet capture provides the actual payload and protocol details of the suspicious traffic, allowing the hunter to confirm whether data is being exfiltrated (e.g., via HTTP POST, DNS tunneling, or custom protocols) and to identify the destination and content. NetFlow only provides metadata (IPs, ports, bytes, timestamps), so packet-level inspection is required to validate the exfiltration hypothesis. This is the most direct confirmatory technique.
Exam trap
CS0-004 often tests the distinction between flow metadata (NetFlow) and payload inspection (packet capture), so candidates must recognize that confirming exfiltration requires seeing the actual data, not just traffic patterns.
How to eliminate wrong answers
Option A is wrong because authentication logs only show whether a user is logged in; they do not reveal what data is being transmitted or to where, and attackers often use compromised service accounts or scheduled tasks. Option B is wrong because checking the registry for persistence identifies how an attacker maintains access, not whether data is being exfiltrated. Option D is wrong because DNS logs may reveal DGA patterns, but the observed traffic is on high-numbered ports to multiple external IPs, not necessarily DNS; reviewing DNS logs would not confirm the actual data transfer.