Courseiva
hardMultiple Choice

ISC2 CC Practice Question: A security analyst receives an alert from the…

A security analyst receives an alert from the SIEM indicating a potential data exfiltration event. The alert shows a large volume of data being transferred to an external IP address during non-business hours. What is the MOST appropriate immediate action?

⚠ Common exam trap

The trap here is assuming that any anomalous data transfer is malicious and requires immediate containment, but the exam expects candidates to recognize that verification is the first step in incident response to avoid false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify whether the transfer is authorized.

The correct answer is to verify whether the transfer is authorized. In incident response, the first step is to validate the alert to determine if it represents a true positive or a false positive. Large data transfers during non-business hours could be legitimate activities such as backups, software updates, or authorized data sharing. Confirming authorization prevents unnecessary escalation and ensures that response efforts are focused on actual threats. This aligns with the 'Identification' phase of incident response, where the goal is to gather evidence and confirm the incident before taking disruptive actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify whether the transfer is authorized.

    Why this is correct

    Confirming whether the transfer was authorised distinguishes legitimate scheduled replication or backup traffic from genuine exfiltration. Acting before verification risks disrupting business operations or destroying evidence, so validation is the immediate step the alert scenario demands.

  • ✗

    Call the employee who owns the server.

    Why it's wrong here

    Contacting the server owner delays containment while exfiltration may still be in progress, and the owner cannot authoritatively confirm whether the transfer is malicious. It is tempting because verifying legitimate business activity with the data owner is valid during triage, but only once the outbound transfer has been stopped.

  • ✗

    Disconnect the affected server from the network.

    Why it's wrong here

    Disconnecting the server halts the transfer but destroys volatile evidence such as active network connections and running processes, and may disrupt business services. It is tempting because isolation is the correct immediate action when malware is actively spreading laterally across multiple hosts.

  • ✗

    Run an antivirus scan on the server.

    Why it's wrong here

    An antivirus scan addresses file-based malware on disk and cannot stop an in-progress outbound transfer, leaving exfiltration ongoing. It is tempting because scanning is the correct first step when a workstation is suspected of harbouring dormant malware with no active network egress observed.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.