Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple SelectObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security analyst is investigating a potential data exfiltration incident. Which three of the following indicators are most commonly associated with a data exfiltration attack? (Choose three.)

⚠ Common exam trap

The SY0-701 exam often tests the distinction between indicators of an active exfiltration event (like data transfer or unusual traffic patterns) and indicators of a precursor attack (like failed logins), so candidates mistakenly select the latter as a direct exfiltration indicator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Unusual outbound network traffic, especially during non-business hours

Unusual outbound network traffic, especially during non-business hours, is a classic indicator of data exfiltration because attackers often schedule transfers when monitoring is less active. Large volumes of data being transferred to an external IP address directly suggests that sensitive data is being moved outside the organization. A sudden increase in DNS queries to a known malicious domain can indicate DNS tunneling, where data is encoded in DNS requests to bypass traditional network controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Unusual outbound network traffic, especially during non-business hours

    Why this is correct

    Unusual outbound network traffic during off-hours is a classic exfiltration indicator because it deviates from the organization's established baseline, suggesting an attacker is moving stolen data when monitoring is less active. The timing outside business hours reduces legitimate background noise, making the anomaly more salient, especially if coupled with a destination that has no business relationship. This pattern may represent a covert channel, encrypted tunnel, or staged upload to a cloud storage service.

  • Multiple failed login attempts from a single user account

    Why it's wrong here

    Multiple failed login attempts against a single user account are a hallmark of credential brute-force or password-spraying activity, not data exfiltration itself. While a successful breach of that account could eventually enable theft, the failed attempts only show an access control attack in progress, producing authentication logs rather than evidence of data leaving the network. In an exfiltration investigation, this would be a supporting precursor, not a primary indicator.

  • Large volumes of data being transferred to an external IP address

    Why this is correct

    Transferring large volumes of data to an external IP address is direct proof of exfiltration because it matches the attacker's objective of copying sensitive information outside the security perimeter. This is particularly suspicious when the volume exceeds the user's normal activity, the destination is not a sanctioned partner, or the traffic uses protocols like HTTPS, FTP, or SMB over the internet in an atypical manner. Analysts should correlate such transfers with database or file-server access logs to confirm the source of the stolen data.

  • A sudden increase in DNS queries to a known malicious domain

    Why this is correct

    A sudden surge in DNS queries to a known malicious domain can indicate DNS tunneling, where attackers encode stolen data into DNS request subdomains to bypass egress filtering. DNS is often allowed through firewalls, making it an attractive covert exfiltration channel, and the high query rate to a domain on a threat-intel list provides a specific, actionable signal. This differs from other indicators because it exploits a trusted protocol and may not register as 'large volume' in traditional bandwidth monitoring.

  • A spike in CPU usage on a database server

    Why it's wrong here

    A spike in CPU usage on a database server is a host-based performance anomaly rather than a network-centric sign of data exfiltration. It could result from legitimate operations such as a resource-intensive query, backup, or maintenance job, and it does not by itself prove that any data left the server. Without matching outbound traffic or data-access logs, this indicator is too ambiguous to implicate exfiltration and might actually point to a denial-of-service or ransomware-related impact.

  • An employee receiving a phishing email with a malicious attachment

    Why it's wrong here

    Receiving a phishing email with a malicious attachment is an infection vector, representing the initial delivery stage of a potential attack, not the exfiltration stage. The mere receipt does not mean the attachment was opened or that data was accessed, and it provides no direct evidence of data leaving the network. In an exfiltration investigation, this would be relevant as a possible attack origin but should be treated as a precursor, requiring further analysis of the attachment and subsequent host activity.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.