hardMultiple Select
CCSP Practice Question: A cloud security engineer is investigating a…
A cloud security engineer is investigating a potential data breach in a cloud environment. The organization uses a cloud access security broker (CASB) and has deployed a security information and event management (SIEM) system. Which of the following are likely indicators that the CASB has detected unauthorized data exfiltration? (Choose two.)
⚠ Common exam trap
The trap is selecting generic security events such as failed logins or malware alerts, which are not exfiltration indicators, instead of the data-movement anomalies a CASB specifically detects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomalous spike in outbound traffic to an unknown IP address
Option A is correct because a CASB monitors cloud traffic and would flag an anomalous spike in outbound traffic to an unknown IP address as a strong indicator of unauthorized data exfiltration, since data is being sent to an untrusted external destination. Option C is correct because a large number of file downloads by a single user outside of business hours is a classic user behavior analytics (UBA) anomaly that a CASB detects, indicating possible bulk data theft by an insider or compromised account. Option B is not a CASB exfiltration indicator; firewall rule changes are configuration events typically surfaced by change management or firewall auditing tools, not CASB traffic analysis. Option D reflects failed authentication attempts, which point to brute-force or credential-stuffing attacks rather than data leaving the environment. Option E is an email security or secure email gateway detection of malware signatures, not a CASB data exfiltration indicator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Anomalous spike in outbound traffic to an unknown IP address
Why this is correct
Anomalous outbound traffic spikes to unknown IP addresses satisfy the exfiltration detection requirement, since CASBs monitor data flows between the organisation and cloud services, flagging volumetric deviations from established baselines. This behavioural signal directly evidences unauthorised data movement, unlike authentication or configuration events, which indicate access attempts rather than confirmed egress.
- ✗
A change in the configuration of a firewall rule
Why it's wrong here
Firewall rule configuration changes are detected by configuration-management or cloud security posture tools, not CASB, which monitors data flows to cloud services rather than network perimeter policy. It tempts because CASBs can enforce firewall-like controls, but that is policy enforcement, not the exfiltration indicator the scenario requires.
- ✓
A large number of file downloads by a single user outside of business hours
Why this is correct
Bulk downloads by one user at unusual hours deviate from that user's established baseline, which the CASB's user behaviour analytics flags as anomalous. This satisfies the stem's requirement for an exfiltration indicator, since volume and timing together signal possible unauthorised data movement.
- ✗
Multiple failed login attempts to a critical application
Why it's wrong here
Repeated failed logins to a critical application indicate brute-force or credential-stuffing attempts, detected by SIEM correlation or identity protection, not CASB exfiltration monitoring. It tempts because CASBs log authentication events to sanctioned apps, but failed logins signal access attempts, not data leaving the environment.
- ✗
An alert for a known malware signature in an email attachment
Why it's wrong here
Signature-based malware detection in an email attachment is an email security gateway or endpoint antivirus function, not CASB exfiltration monitoring, which watches data movement to unsanctioned cloud services. It tempts because CASB inline proxies can scan attachments, but that addresses inbound threat prevention rather than outbound unauthorised data transfer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.