Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is reviewing NetFlow data and notices a large amount of data being transferred from an internal database server to an external IP address on port 443 during non-business hours. The database server is not expected to initiate outbound connections. Which type of activity is most likely occurring?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data exfiltration

The data transfer is large, to an external IP, on an encrypted port, outside business hours, and from a server that shouldn't initiate outbound connections. This strongly suggests data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Domain generation algorithm (DGA)

    Why it's wrong here

    Domain generation algorithms (DGAs) are utilized by malware to dynamically generate a high volume of pseudo-random domain names for command-and-control (C2) communications. NetFlow data of a DGA would typically show numerous failed DNS queries or short-lived connections to diverse domains, rather than a sustained, high-volume data transfer to a single external IP address.

  • ✗

    Lateral movement

    Why it's wrong here

    Lateral movement describes an attacker's progression through an internal network to compromise additional hosts and locate high-value assets. This activity is characterized by east-west traffic patterns between internal subnets, such as RDP, SSH, or SMB connections, whereas a massive outbound transfer to an external destination represents north-south egress traffic.

  • ✓

    Data exfiltration

    Why this is correct

    Data exfiltration involves the unauthorized transfer of sensitive information from an internal network to an external, attacker-controlled destination. In NetFlow analysis, this is typically flagged by an anomalous, large-volume outbound connection (north-south traffic) originating from an internal host to an unfamiliar external IP address, especially outside of normal business hours.

  • ✗

    Normal backup activity

    Why it's wrong here

    While normal backup operations do involve transferring large volumes of data, they are highly structured, scheduled events that target known, authorized offsite or cloud-based backup repositories. An unexpected, unscheduled spike in outbound traffic to an unverified or anomalous external IP address deviates from this established baseline, pointing to malicious activity rather than routine maintenance.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.