SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst is investigating a potential data exfiltration incident. Which three of the following indicators are most commonly associated with a data exfiltration attack? (Choose three.)
⚠ Common exam trap
The SY0-701 exam often tests the distinction between indicators of an active exfiltration event (like data transfer or unusual traffic patterns) and indicators of a precursor attack (like failed logins), so candidates mistakenly select the latter as a direct exfiltration indicator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unusual outbound network traffic, especially during non-business hours
Unusual outbound network traffic, especially during non-business hours, is a classic indicator of data exfiltration because attackers often schedule transfers when monitoring is less active. Large volumes of data being transferred to an external IP address directly suggests that sensitive data is being moved outside the organization. A sudden increase in DNS queries to a known malicious domain can indicate DNS tunneling, where data is encoded in DNS requests to bypass traditional network controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unusual outbound network traffic, especially during non-business hours
Why this is correct
Unusual outbound network traffic during off-hours is a classic exfiltration indicator because it deviates from the organization's established baseline, suggesting an attacker is moving stolen data when monitoring is less active. The timing outside business hours reduces legitimate background noise, making the anomaly more salient, especially if coupled with a destination that has no business relationship. This pattern may represent a covert channel, encrypted tunnel, or staged upload to a cloud storage service.
- ✗
Multiple failed login attempts from a single user account
Why it's wrong here
Multiple failed login attempts against a single user account are a hallmark of credential brute-force or password-spraying activity, not data exfiltration itself. While a successful breach of that account could eventually enable theft, the failed attempts only show an access control attack in progress, producing authentication logs rather than evidence of data leaving the network. In an exfiltration investigation, this would be a supporting precursor, not a primary indicator.
- ✓
Large volumes of data being transferred to an external IP address
Why this is correct
Transferring large volumes of data to an external IP address is direct proof of exfiltration because it matches the attacker's objective of copying sensitive information outside the security perimeter. This is particularly suspicious when the volume exceeds the user's normal activity, the destination is not a sanctioned partner, or the traffic uses protocols like HTTPS, FTP, or SMB over the internet in an atypical manner. Analysts should correlate such transfers with database or file-server access logs to confirm the source of the stolen data.
- ✓
A sudden increase in DNS queries to a known malicious domain
Why this is correct
A sudden surge in DNS queries to a known malicious domain can indicate DNS tunneling, where attackers encode stolen data into DNS request subdomains to bypass egress filtering. DNS is often allowed through firewalls, making it an attractive covert exfiltration channel, and the high query rate to a domain on a threat-intel list provides a specific, actionable signal. This differs from other indicators because it exploits a trusted protocol and may not register as 'large volume' in traditional bandwidth monitoring.
- ✗
A spike in CPU usage on a database server
Why it's wrong here
A spike in CPU usage on a database server is a host-based performance anomaly rather than a network-centric sign of data exfiltration. It could result from legitimate operations such as a resource-intensive query, backup, or maintenance job, and it does not by itself prove that any data left the server. Without matching outbound traffic or data-access logs, this indicator is too ambiguous to implicate exfiltration and might actually point to a denial-of-service or ransomware-related impact.
- ✗
An employee receiving a phishing email with a malicious attachment
Why it's wrong here
Receiving a phishing email with a malicious attachment is an infection vector, representing the initial delivery stage of a potential attack, not the exfiltration stage. The mere receipt does not mean the attachment was opened or that data was accessed, and it provides no direct evidence of data leaving the network. In an exfiltration investigation, this would be relevant as a possible attack origin but should be treated as a precursor, requiring further analysis of the attachment and subsequent host activity.
Go deeper
Related to this question
Learn chapter
Network-Based Attacks
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.