hardMultiple Choice
ISC2 CC Practice Question: A security analyst receives an alert from the…
A security analyst receives an alert from the SIEM indicating a potential data exfiltration event. The alert shows a large volume of data being transferred to an external IP address during non-business hours. What is the MOST appropriate immediate action?
⚠ Common exam trap
The trap here is assuming that any anomalous data transfer is malicious and requires immediate containment, but the exam expects candidates to recognize that verification is the first step in incident response to avoid false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify whether the transfer is authorized.
The correct answer is to verify whether the transfer is authorized. In incident response, the first step is to validate the alert to determine if it represents a true positive or a false positive. Large data transfers during non-business hours could be legitimate activities such as backups, software updates, or authorized data sharing. Confirming authorization prevents unnecessary escalation and ensures that response efforts are focused on actual threats. This aligns with the 'Identification' phase of incident response, where the goal is to gather evidence and confirm the incident before taking disruptive actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify whether the transfer is authorized.
Why this is correct
Confirming whether the transfer was authorised distinguishes legitimate scheduled replication or backup traffic from genuine exfiltration. Acting before verification risks disrupting business operations or destroying evidence, so validation is the immediate step the alert scenario demands.
- ✗
Call the employee who owns the server.
Why it's wrong here
Contacting the server owner delays containment while exfiltration may still be in progress, and the owner cannot authoritatively confirm whether the transfer is malicious. It is tempting because verifying legitimate business activity with the data owner is valid during triage, but only once the outbound transfer has been stopped.
- ✗
Disconnect the affected server from the network.
Why it's wrong here
Disconnecting the server halts the transfer but destroys volatile evidence such as active network connections and running processes, and may disrupt business services. It is tempting because isolation is the correct immediate action when malware is actively spreading laterally across multiple hosts.
- ✗
Run an antivirus scan on the server.
Why it's wrong here
An antivirus scan addresses file-based malware on disk and cannot stop an in-progress outbound transfer, leaving exfiltration ongoing. It is tempting because scanning is the correct first step when a workstation is suspected of harbouring dormant malware with no active network egress observed.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
True positive
A true positive is when a security tool correctly identifies a real threat or malicious activity.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.