Courseiva
Security Operations →hardMultiple Choice

CISSP Security Operations Practice Question

A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?

⚠ Common exam trap

CISSP often tests whether candidates can distinguish the underlying cause (malware, unauthorized access) from the resulting incident classification (data breach) based on the evidence presented.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data breach

Large outbound data transfers from a sensitive database server to an external IP during non-business hours strongly indicate exfiltration, which is the hallmark of a data breach. The volume, sensitivity of the source, and off-hours timing all point to unauthorized data movement rather than other incident types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Unauthorized access

    Why it's wrong here

    Unauthorized access describes the initial compromise or gaining of illicit entry into a system or network. While often a prerequisite for data exfiltration, the SIEM alert specifically flags the *movement* of data out of the network, which is the direct manifestation of a data breach, rather than just the initial access event. The alert points to the consequence of data leaving, not merely the act of gaining entry.

  • ✗

    Denial of Service (DoS)

    Why it's wrong here

    Denial of Service (DoS) attacks are fundamentally aimed at disrupting the availability of services or resources by overwhelming them with traffic or requests, making them inaccessible to legitimate users. This type of incident does not involve the unauthorized extraction or transfer of data from the network, which is the core activity indicated by the SIEM alert. DoS focuses on service disruption, not data compromise.

  • ✗

    Malware infection

    Why it's wrong here

    Malware infection refers to the successful compromise of a system by malicious software. While certain malware types, like Trojans or spyware, can facilitate data exfiltration, the SIEM alert directly reports the *outcome* of data leaving the network, which is the incident itself. The infection is a potential root cause, but the primary incident described is the unauthorized data transfer, not merely the presence of malware.

  • ✓

    Data breach

    Why this is correct

    A data breach is precisely defined as the unauthorized access, disclosure, or exfiltration of sensitive, protected, or confidential information. The SIEM alert indicating unauthorized data transfer out of the network directly describes the core characteristic of a data breach, where data has left the secure perimeter without proper authorization. This makes it the most accurate classification for an incident involving data exfiltration.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.