Courseiva
hardMultiple Select

CS0-003 Practice Question: Which THREE of the following are common…

Which THREE of the following are common indicators of a data exfiltration attempt? (Choose three.)

⚠ Common exam trap

CompTIA often tests the distinction between indicators of exfiltration (data leaving) versus indicators of initial access or lateral movement, so candidates may confuse failed logins (Option E) with exfiltration when it actually points to a different phase of the attack chain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Outbound connections to IP addresses associated with known C2 servers

Outbound connections to IP addresses associated with known command-and-control (C2) servers are a classic indicator of data exfiltration. Once an attacker establishes a C2 channel, they can use it to tunnel stolen data out of the network. Security tools like firewalls and threat intelligence feeds flag these connections based on known malicious IP addresses or domains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Outbound connections to IP addresses associated with known C2 servers

    Why this is correct

    Outbound traffic to IP addresses matching known command-and-control infrastructure is a direct indicator that a compromised host is actively communicating with attacker-controlled systems, which is frequently the channel used to receive further instructions or stage stolen data before it leaves the network, making C2 IP matches a high-confidence exfiltration signal when correlated with threat intelligence feeds.

  • ✓

    DNS queries with high entropy subdomains

    Why this is correct

    DNS queries containing high-entropy, randomized-looking subdomains such as a3f8b2c1.malicious.com indicate DNS tunneling, a technique attackers use to encode stolen data into the DNS protocol itself because DNS traffic is rarely inspected as closely as HTTP or HTTPS by traditional network filters, letting exfiltration slip past firewalls that focus on more obvious data channels.

  • ✗

    Increased use of encrypted communication protocols

    Why it's wrong here

    Increased encrypted traffic by itself is not a reliable exfiltration indicator because the overwhelming majority of legitimate business communication, cloud backups, and SaaS traffic is encrypted by default under TLS; flagging every rise in encrypted volume would generate massive false positives without the additional context of destination reputation, volume anomaly, or timing that actually signals malicious activity.

  • ✓

    Unusually large outbound data transfers during off-hours

    Why this is correct

    A sudden spike in outbound data volume occurring outside normal business hours deviates from an established network traffic baseline and suggests an automated or attacker-driven transfer timed to avoid detection by staff who would notice unusual activity during the day, making off-hours volume anomalies a classic behavioral indicator that NetFlow or Zeek-based monitoring is tuned to catch.

  • ✗

    Multiple failed login attempts from a single source

    Why it's wrong here

    Repeated failed logins from one source point to a credential brute-force or password-spraying attempt during the initial access phase of the attack chain, not the later exfiltration phase where data actually leaves the network; this option tests whether the candidate can distinguish an inbound authentication attack from an outbound data-loss indicator.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.