SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security analyst is configuring a SIEM to detect potential data exfiltration. Which TWO log sources are most critical for detecting large outbound data transfers?
⚠ Common exam trap
A common pitfall is to think that DNS logs are sufficient for detecting exfiltration via DNS tunneling, but the question specifically asks for detecting 'large outbound data transfers,' which require volume-based analysis from network flow logs or proxy logs, not just query patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network flow logs (e.g., NetFlow)
Network flow logs (Option A) are critical because NetFlow/IPFIX records capture byte and packet counts per flow, letting the SIEM baseline normal egress volumes and alert on anomalously large outbound transfers to external IPs. Proxy logs (Option C) are equally critical because they record HTTP/HTTPS requests with URLs, destination hosts, and often response/request sizes, exposing web-based exfiltration such as large uploads to cloud storage or file-sharing sites. Together these two sources give both volumetric (flow) and content-context (proxy) visibility into outbound data movement. DNS logs (B) mainly reveal tunneling or beaconing via query patterns and payload sizes, not bulk data transfer volumes. System event logs (D) and application error logs (E) are host-local and generally lack the outbound network volume and destination detail needed to detect large data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Network flow logs (e.g., NetFlow)
Why this is correct
Network flow logs record byte and packet counts per connection, exposing volumetric anomalies such as unusually large outbound transfers that endpoint or application logs would miss. This directly satisfies the SIEM's requirement to detect data exfiltration by revealing the volume and destination of traffic leaving the network, independent of payload content.
- ✗
DNS logs
Why it's wrong here
DNS logs show queried names and resolutions, exposing tunnelling or beaconing domains, but not the byte counts of bulk transfers. Firewall and proxy logs, which record session volume and destination, are critical for spotting large outbound movements. DNS suits command-and-control detection instead.
- ✓
Proxy logs
Why this is correct
Proxy logs capture outbound HTTP and HTTPS requests with URLs, destinations and transferred bytes, revealing large uploads to external sites. This satisfies the stem's exfiltration detection need by exposing application-layer egress that network flow metadata alone cannot attribute.
- ✗
System event logs
Why it's wrong here
System event logs record host-level activity such as service starts and authentication, not byte volumes crossing the network perimeter. Firewall and proxy logs, which capture session sizes and destinations, are critical for spotting bulk outbound transfers. System logs suit host intrusion or privilege-escalation detection instead.
- ✗
Application error logs
Why it's wrong here
Application error logs capture exceptions and stack traces, revealing crashes rather than outbound traffic volumes. NetFlow and firewall logs, which record bytes and destinations per connection, are critical for detecting exfiltration. Error logs are the right source for diagnosing application faults or injection attempts.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.