Courseiva
Security OperationshardMultiple SelectObjective-mapped

CS0-003 Security Operations Practice Question

An analyst is investigating a potential data exfiltration incident. The analyst observes repeated HTTPS connections to a cloud storage provider from a server that does not normally use that service. Which three additional artifacts would strengthen the case for exfiltration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The data transfer volume is significantly higher than normal for that server

Large outbound data volume, connections outside business hours, and use of non-standard ports (e.g., 443 for https but custom port for tunneling) are classic exfiltration indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The data transfer volume is significantly higher than normal for that server

    Why this is correct

    A sudden or sustained increase in outbound data volume compared to the server's rolling baseline is one of the strongest indicators of exfiltration. Attackers often stage, compress, and encrypt data before bulk transfer to avoid detection, which typically manifests as an anomalous spike in bytes sent from the server. This signal is only meaningful when juxtaposed with the server's historical traffic patterns, so without baselining, a high volume could be dismissed as routine maintenance or backup activity.

  • The connections are occurring during non-business hours

    Why this is correct

    Connections that occur during non-business hours are suspicious because they deviate from the expected operational schedule of the server, especially if the server normally has low off-hours traffic. Attackers frequently time exfiltration to run late at night or on weekends to minimize the chance of immediate observation by staff and to blend with automated backups or scheduled jobs. This behavioral anomaly becomes even more compelling when the off-hours traffic also involves unusual destinations or data volumes.

  • The connections are made to a known malicious IP

    Why it's wrong here

    This is incorrect because attackers frequently exfiltrate data to legitimate cloud services, file-sharing platforms, or SaaS applications whose IP ranges are not flagged on threat intelligence lists. A connection to a known-malicious IP would be a strong indicator, but its absence does not rule out exfiltration—in fact, modern exfiltration often deliberately avoids such IPs to evade blacklist-based detection. Additionally, threat intelligence entries can become stale, so relying solely on this signal would miss many real data-theft scenarios.

  • The connections occur during business hours only

    Why it's wrong here

    This is incorrect because exfiltration can absolutely occur during business hours, and many servers only operate during normal working hours, making business-hours connections the norm rather than an anomaly. Attackers may intentionally operate within legitimate workflows to blend in, or they may use the high volume of daytime traffic as cover to hide their activity. A static rule that treats business-hours traffic as benign would not only miss exfiltration but also generate false negatives when the exfiltration is embedded in a large volume of otherwise valid sessions.

  • The server is using a non-standard port for HTTPS (e.g., 8080)

    Why this is correct

    Using a non-standard port for HTTPS, such as 8080 or 8443, is a strong indicator because it breaks from the conventional port 443 and often signals an attempt to evade egress filtering or protocol-aware inspection. While some legitimate applications do use alternate ports, if the server normally communicates only over standard HTTPS, this deviation can indicate tunneling, proxy usage, or command-and-control traffic. Non-standard ports also tend to be ignored by monitoring tools that only inspect 443, allowing exfiltrated data to slip through without deep packet analysis.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.