Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

During a network breach investigation, an analyst examines NetFlow records and sees large data transfers from a server to an external IP address during off-hours. Which type of activity does this MOST likely indicate?

⚠ Common exam trap

EC-CHFI often tests the distinction between outbound data flows (exfiltration) and inbound traffic (DoS), so the trap here is confusing the direction of the traffic—candidates may pick DoS because they associate large transfers with attacks, but DoS targets the server with inbound floods, not outbound data theft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data exfiltration by an attacker

Large data transfers from a server to an external IP address during off-hours are a classic indicator of data exfiltration. NetFlow records capture metadata such as source/destination IPs, ports, and byte counts; a sudden, high-volume outbound flow to an unfamiliar external IP outside normal business hours strongly suggests an attacker is copying sensitive data out of the network, not legitimate traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Normal software update download

    Why it's wrong here

    Normal software update downloads are inbound by nature: the server initiates connections to vendor update repositories and pulls patched binaries over HTTPS. A large, one-way outbound transfer to an unknown external IP during off-hours does not match that model, because updates do not involve the server sending its own local data outward. Furthermore, update traffic comes from known, signed sources and is logged by the update agent, which would be absent in this scenario.

  • ✗

    Scheduled backup to a cloud service

    Why it's wrong here

    Legitimate scheduled backups are configured with specific destination endpoints, such as a known cloud provider's storage bucket or IP range, and typically use service accounts with pre-authorized credentials. While backups can legitimately run off-hours and involve large volumes of encrypted data, the key anomaly here is that the destination is an unfamiliar external IP that has no prior history in netflow. An attacker could also encrypt data, so the presence of encryption alone does not distinguish a backup from exfiltration; the burst pattern, first-time connection, and lack of matching backup job logs point away from this explanation.

  • ✓

    Data exfiltration by an attacker

    Why this is correct

    Data exfiltration is the correct interpretation because an attacker who has gained access will often locate and stage sensitive files, compress and encrypt them to avoid detection, and then transmit that archive to an external server they control. The combination of large outbound traffic, off-hours timing, and an unknown destination IP is a classic indicator of the exfiltration phase of an intrusion. This aligns with the MITRE ATT&CK technique T1048 (Exfiltration Over Alternative Protocol) and warrants immediate correlation with process execution and endpoint logs to identify the staging artifacts.

  • ✗

    Denial-of-service attack against the server

    Why it's wrong here

    A denial-of-service (DoS) attack against the server is characterized by overwhelming inbound traffic—such as a SYN flood, UDP amplification, or HTTP request flood—that consumes the server's resources and renders it unavailable. In that scenario, the observable network anomaly is a massive incoming packet rate or connection count, not a large outbound data transfer of local files. The described evidence of a bulk outbound transfer is directly opposite the traffic direction expected during a DoS, and therefore this option cannot explain the observed network activity.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.