Courseiva
hardMultiple Select

ISC2 CC Practice Question: A security operations center (SOC) analyst is…

A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?

⚠ Common exam trap

ISC2 often tests the distinction between indicators of compromise (IOCs) for different attack phases—candidates confuse C2 beaconing (DNS queries) with data exfiltration (large file transfers), or mistake authentication failures for exfiltration activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unexpected large file transfers via FTP

Option C is correct because unexpected large file transfers via FTP are a classic exfiltration indicator: FTP (ports 20/21) is a cleartext file-transfer protocol, and a sudden, high-volume upload to an external server strongly suggests data being moved out of the environment. Option E is correct because unusual outbound traffic to a foreign IP indicates beaconing or bulk data transfer to an external command-and-control or staging host, which is a hallmark of exfiltration, especially when the destination is atypical for the organization. Option A is not correct because a large number of failed login attempts indicates brute-force or password-spraying activity against authentication, which is an intrusion attempt rather than evidence of data leaving the network. Option B is not correct because frequent DNS queries to known malicious domains point to malware beaconing, command-and-control communication, or domain generation algorithm activity, which is a precursor or concurrent compromise indicator, not exfiltration itself. Option D is not correct because multiple antivirus alerts indicate malware detection or endpoint compromise, which may precede exfiltration but does not by itself demonstrate that data was transferred out.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Large number of failed login attempts

    Why it's wrong here

    Large failed-login volumes indicate brute-force or credential-stuffing attempts against authentication endpoints, not outbound data movement. Exfiltration requires evidence of data leaving, such as anomalous outbound transfer volumes or connections to unrecognised destinations. Failed logins are tempting because they signal active intrusion, and would be the correct indicator when investigating password-guessing or account lockout activity.

  • ✗

    Frequent DNS queries to known malicious domains

    Why it's wrong here

    DNS queries to malicious domains show command-and-control or beaconing traffic, which is outbound communication rather than bulk data transfer. It is tempting because C2 often precedes exfiltration, and would be correct when identifying an active compromised host's callback channel.

  • ✓

    Unexpected large file transfers via FTP

    Why this is correct

    Exfiltration requires outbound data movement, and unusually large FTP transfers to external or unfamiliar hosts indicate bulk data leaving the network. This volume and direction anomaly distinguishes exfiltration from routine inbound traffic or normal file access, directly satisfying the stem's requirement for a likely sign of data exfiltration.

  • ✗

    Multiple antivirus alerts

    Why it's wrong here

    Antivirus alerts indicate malware detection on endpoints, not the transfer of data outside the organisation. It is tempting because malware frequently enables exfiltration, and would be correct when triaging infected hosts rather than confirming data left the network.

  • ✓

    Unusual outbound traffic to a foreign IP

    Why this is correct

    Outbound connections to foreign or unexpected IP addresses can indicate command-and-control or exfiltration channels, especially when volume, timing or destination deviates from the host's baseline. Correlating this with data volume anomalies strengthens the exfiltration hypothesis.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.