Courseiva
hardMultiple Select

CISA Practice Question: Which THREE are indicators of a possible data…

Which THREE are indicators of a possible data exfiltration attempt via the network? (Choose three.)

⚠ Common exam trap

ISACA often tests the distinction between precursors to an attack (like phishing) and actual indicators of exfiltration (like unauthorized tunneling or unusual outbound volumes), so candidates mistakenly choose phishing because it is a common attack vector, but it is not a network-level exfiltration indicator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use of unauthorized encryption or tunneling protocols

Option A is correct because attackers commonly hide stolen data inside unauthorized encryption or tunneling protocols (e.g., DNS tunneling, SSH, or custom TLS on nonstandard ports) to evade content inspection and DLP controls, making it a strong network exfiltration indicator. Option B is correct because exfiltration frequently occurs during non-business hours to avoid detection, and abnormal outbound volume spikes at those times deviate from the baseline of normal traffic behavior. Option D is correct because repeated unauthorized access attempts to sensitive databases indicate an adversary probing or harvesting data, which often precedes or accompanies exfiltration over the network. Option C is not a network exfiltration indicator; phishing emails targeting executives are an initial access or social-engineering tactic, not evidence of data leaving the network. Option E is not inherently suspicious because numerous HTTPS connections to legitimate cloud services are common in normal business operations and are only meaningful if correlated with other anomalies such as unusual volume, timing, or destination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use of unauthorized encryption or tunneling protocols

    Why this is correct

    Unauthorised encryption or tunnelling protocols conceal payload contents from inspection appliances, letting attackers move data past DLP and firewall controls. Legitimate services rarely introduce new tunnels, so their sudden appearance signals possible exfiltration rather than normal egress traffic.

  • ✓

    Unusual outbound data transfer volumes during non-business hours

    Why this is correct

    Exfiltration requires moving data out, so abnormally large outbound volumes outside working hours signal bulk transfer when monitoring is thin. This timing and volume anomaly distinguishes malicious extraction from routine daytime backup or replication traffic.

  • ✗

    Increase in phishing emails targeting executives

    Why it's wrong here

    Phishing emails targeting executives indicate a possible precursor or social-engineering campaign, not data leaving the network. It is tempting because phishing often precedes exfiltration, and would be correct as an indicator of an intrusion attempt rather than of outbound data transfer.

  • ✓

    Repeated access attempts to sensitive databases by unauthorized users

    Why this is correct

    Unauthorised users repeatedly querying sensitive databases signals reconnaissance or collection consistent with exfiltration staging. Such anomalous access patterns, especially repeated attempts against protected data stores, indicate data is being targeted for extraction across the network.

  • ✗

    Large number of HTTPS connections to legitimate cloud services

    Why it's wrong here

    HTTPS to legitimate cloud services is normal business traffic; volume alone does not indicate exfiltration unless baselines are exceeded or destinations are anomalous. It is tempting because exfiltration often hides in encrypted cloud traffic, and would be correct when such connections deviate markedly from established patterns.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.