hardMultiple Select
ISC2 CC Practice Question: A security operations center (SOC) analyst is…
A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?
⚠ Common exam trap
ISC2 often tests the distinction between indicators of compromise (IOCs) for different attack phases—candidates confuse C2 beaconing (DNS queries) with data exfiltration (large file transfers), or mistake authentication failures for exfiltration activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unexpected large file transfers via FTP
Option C is correct because unexpected large file transfers via FTP are a classic exfiltration indicator: FTP (ports 20/21) is a cleartext file-transfer protocol, and a sudden, high-volume upload to an external server strongly suggests data being moved out of the environment. Option E is correct because unusual outbound traffic to a foreign IP indicates beaconing or bulk data transfer to an external command-and-control or staging host, which is a hallmark of exfiltration, especially when the destination is atypical for the organization. Option A is not correct because a large number of failed login attempts indicates brute-force or password-spraying activity against authentication, which is an intrusion attempt rather than evidence of data leaving the network. Option B is not correct because frequent DNS queries to known malicious domains point to malware beaconing, command-and-control communication, or domain generation algorithm activity, which is a precursor or concurrent compromise indicator, not exfiltration itself. Option D is not correct because multiple antivirus alerts indicate malware detection or endpoint compromise, which may precede exfiltration but does not by itself demonstrate that data was transferred out.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Large number of failed login attempts
Why it's wrong here
Large failed-login volumes indicate brute-force or credential-stuffing attempts against authentication endpoints, not outbound data movement. Exfiltration requires evidence of data leaving, such as anomalous outbound transfer volumes or connections to unrecognised destinations. Failed logins are tempting because they signal active intrusion, and would be the correct indicator when investigating password-guessing or account lockout activity.
- ✗
Frequent DNS queries to known malicious domains
Why it's wrong here
DNS queries to malicious domains show command-and-control or beaconing traffic, which is outbound communication rather than bulk data transfer. It is tempting because C2 often precedes exfiltration, and would be correct when identifying an active compromised host's callback channel.
- ✓
Unexpected large file transfers via FTP
Why this is correct
Exfiltration requires outbound data movement, and unusually large FTP transfers to external or unfamiliar hosts indicate bulk data leaving the network. This volume and direction anomaly distinguishes exfiltration from routine inbound traffic or normal file access, directly satisfying the stem's requirement for a likely sign of data exfiltration.
- ✗
Multiple antivirus alerts
Why it's wrong here
Antivirus alerts indicate malware detection on endpoints, not the transfer of data outside the organisation. It is tempting because malware frequently enables exfiltration, and would be correct when triaging infected hosts rather than confirming data left the network.
- ✓
Unusual outbound traffic to a foreign IP
Why this is correct
Outbound connections to foreign or unexpected IP addresses can indicate command-and-control or exfiltration channels, especially when volume, timing or destination deviates from the host's baseline. Correlating this with data volume anomalies strengthens the exfiltration hypothesis.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
SOC
A Security Operations Center (SOC) is a centralized team that monitors, detects, analyzes, and responds to cybersecurity incidents to protect an organization's information systems.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.