Courseiva
Security Operations →hardMultiple Select

ISC2 CC Security Operations Practice Question

A security operations center (SOC) is reviewing its incident response plan and wants to improve detection of data exfiltration over encrypted channels. Which TWO monitoring approaches would BEST help identify potential exfiltration in this scenario? (Choose two.)

⚠ Common exam trap

The trap here is assuming that decrypting all traffic is necessary or always feasible, when in fact behavioral and metadata analysis often provide better detection for encrypted exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyzing network flow records for unusual volumes of outbound traffic to external IP addresses

Detecting encrypted exfiltration requires focusing on behavior and metadata rather than payload content. Network flow analysis identifies anomalous outbound volumes, while endpoint monitoring detects staging activities like archiving. Together, they provide complementary visibility without relying on decryption, making them effective for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Analyzing network flow records for unusual volumes of outbound traffic to external IP addresses

    Why this is correct

    Network flow records, such as NetFlow or IPFIX, provide metadata about connections without payload inspection. Large or anomalous outbound data transfers to external IPs can indicate exfiltration even when traffic is encrypted. This approach is effective because it focuses on behavior and volume rather than content, making it suitable for detecting encrypted exfiltration.

  • ✗

    Enabling full packet capture and storing all network traffic for later analysis

    Why it's wrong here

    Full packet capture generates enormous data volumes and is often impractical for long-term storage. While it can be useful for forensic analysis, it does not provide real-time detection of encrypted exfiltration and may be cost-prohibitive. It is not a proactive monitoring approach for identifying ongoing exfiltration.

  • ✗

    Reviewing DNS query logs for lookups of known malicious domains

    Why it's wrong here

    DNS query logs can reveal connections to malicious domains, but they do not directly indicate data exfiltration over encrypted channels. Attackers may use domain generation algorithms or compromised legitimate domains, and DNS lookups alone do not show data volume or transfer. Thus, it is less effective for detecting actual exfiltration.

  • ✓

    Monitoring endpoint logs for processes that compress and archive large numbers of files

    Why this is correct

    Attackers often stage data by compressing and archiving files before exfiltration. Endpoint monitoring can detect unusual archiving activity, such as a non-standard process creating large ZIP or RAR files. This behavior-based detection complements network monitoring and can catch exfiltration preparation even if the transfer itself is encrypted.

  • ✗

    Deploying SSL/TLS inspection to decrypt and examine all outbound web traffic

    Why it's wrong here

    While SSL/TLS inspection can reveal payload content, it is not always feasible due to privacy, legal, and performance concerns. It may also break certificate pinning and cause operational issues. Moreover, sophisticated attackers may use non-web protocols or custom encryption. Therefore, it is not the best primary approach for detecting encrypted exfiltration.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.