Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security analyst is configuring a SIEM to detect potential data exfiltration. Which TWO log sources are most critical for detecting large outbound data transfers?

⚠ Common exam trap

A common pitfall is to think that DNS logs are sufficient for detecting exfiltration via DNS tunneling, but the question specifically asks for detecting 'large outbound data transfers,' which require volume-based analysis from network flow logs or proxy logs, not just query patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network flow logs (e.g., NetFlow)

Network flow logs (Option A) are critical because NetFlow/IPFIX records capture byte and packet counts per flow, letting the SIEM baseline normal egress volumes and alert on anomalously large outbound transfers to external IPs. Proxy logs (Option C) are equally critical because they record HTTP/HTTPS requests with URLs, destination hosts, and often response/request sizes, exposing web-based exfiltration such as large uploads to cloud storage or file-sharing sites. Together these two sources give both volumetric (flow) and content-context (proxy) visibility into outbound data movement. DNS logs (B) mainly reveal tunneling or beaconing via query patterns and payload sizes, not bulk data transfer volumes. System event logs (D) and application error logs (E) are host-local and generally lack the outbound network volume and destination detail needed to detect large data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network flow logs (e.g., NetFlow)

    Why this is correct

    Network flow logs record byte and packet counts per connection, exposing volumetric anomalies such as unusually large outbound transfers that endpoint or application logs would miss. This directly satisfies the SIEM's requirement to detect data exfiltration by revealing the volume and destination of traffic leaving the network, independent of payload content.

  • ✗

    DNS logs

    Why it's wrong here

    DNS logs show queried names and resolutions, exposing tunnelling or beaconing domains, but not the byte counts of bulk transfers. Firewall and proxy logs, which record session volume and destination, are critical for spotting large outbound movements. DNS suits command-and-control detection instead.

  • ✓

    Proxy logs

    Why this is correct

    Proxy logs capture outbound HTTP and HTTPS requests with URLs, destinations and transferred bytes, revealing large uploads to external sites. This satisfies the stem's exfiltration detection need by exposing application-layer egress that network flow metadata alone cannot attribute.

  • ✗

    System event logs

    Why it's wrong here

    System event logs record host-level activity such as service starts and authentication, not byte volumes crossing the network perimeter. Firewall and proxy logs, which capture session sizes and destinations, are critical for spotting bulk outbound transfers. System logs suit host intrusion or privilege-escalation detection instead.

  • ✗

    Application error logs

    Why it's wrong here

    Application error logs capture exceptions and stack traces, revealing crashes rather than outbound traffic volumes. NetFlow and firewall logs, which record bytes and destinations per connection, are critical for detecting exfiltration. Error logs are the right source for diagnosing application faults or injection attempts.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.