Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security analyst is reviewing SIEM alerts and wants to identify potential data exfiltration. Which TWO of the following indicators are most relevant?

⚠ Common exam trap

Test-takers frequently confuse indicators of compromise (like failed logins or CPU spikes) with exfiltration-specific signs, failing to focus on outbound data movement as the core criterion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Large outbound data transfers to an external IP

Option B is correct because large outbound data transfers to an external IP are a classic exfiltration indicator: data leaving the network in abnormal volume or to an unfamiliar destination suggests staging and transfer of stolen data, and SIEM correlation on bytes sent, destination reputation, and baseline deviation is the standard detection method. Option C is correct because a user or host connecting to a known command-and-control (C2) server indicates active adversary communication, which typically precedes or accompanies exfiltration and is detected via threat-intelligence feeds, DNS/HTTP beaconing patterns, and IOC matching. Option A does not belong because successful logins during business hours are normal expected activity and lack exfiltration context. Option D does not belong because multiple failed login attempts indicate brute-force or credential-stuffing attempts (an access/integrity threat), not outbound data theft. Option E does not belong because elevated CPU usage on a database server is a performance or resource symptom that may have many benign causes and is not a direct exfiltration indicator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Successful logins during business hours

    Why it's wrong here

    Successful business-hours logins are routine authentication events, not exfiltration signals; they show access, not data movement. This indicator belongs in a baseline of normal behaviour, where deviations from it would be flagged. Detecting exfiltration instead requires monitoring outbound volume, destination, or unusual transfer timing.

  • ✓

    Large outbound data transfers to an external IP

    Why this is correct

    Exfiltration requires data leaving the network, so unusually large outbound transfers to an external IP directly indicate possible data theft. Volume and destination are the measurable network-flow characteristics that distinguish exfiltration from normal egress traffic.

  • ✓

    A user connecting to a known command-and-control server

    Why this is correct

    Contact with a known command-and-control server indicates an established attacker channel, a hallmark of compromised hosts staging or exfiltrating data. This destination-based indicator complements volume analysis by revealing the adversary infrastructure receiving the stolen information.

  • ✗

    Multiple failed login attempts

    Why it's wrong here

    Multiple failed login attempts indicate brute-force or credential-stuffing activity against authentication, not outbound data movement. It tempts because failed logins are a classic SIEM alert, but exfiltration detection requires indicators such as anomalous outbound transfer volumes or unusual destination addresses, not authentication failures.

  • ✗

    Elevated CPU usage on a database server

    Why it's wrong here

    Elevated CPU usage on a database server may reflect legitimate query load, indexing, or maintenance, and does not itself demonstrate data leaving the environment. It tempts because resource spikes often accompany suspicious activity, but exfiltration indicators concern outbound data volume and destinations, not processor utilisation.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.