SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security analyst is reviewing SIEM alerts and wants to identify potential data exfiltration. Which TWO of the following indicators are most relevant?
⚠ Common exam trap
Test-takers frequently confuse indicators of compromise (like failed logins or CPU spikes) with exfiltration-specific signs, failing to focus on outbound data movement as the core criterion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Large outbound data transfers to an external IP
Option B is correct because large outbound data transfers to an external IP are a classic exfiltration indicator: data leaving the network in abnormal volume or to an unfamiliar destination suggests staging and transfer of stolen data, and SIEM correlation on bytes sent, destination reputation, and baseline deviation is the standard detection method. Option C is correct because a user or host connecting to a known command-and-control (C2) server indicates active adversary communication, which typically precedes or accompanies exfiltration and is detected via threat-intelligence feeds, DNS/HTTP beaconing patterns, and IOC matching. Option A does not belong because successful logins during business hours are normal expected activity and lack exfiltration context. Option D does not belong because multiple failed login attempts indicate brute-force or credential-stuffing attempts (an access/integrity threat), not outbound data theft. Option E does not belong because elevated CPU usage on a database server is a performance or resource symptom that may have many benign causes and is not a direct exfiltration indicator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Successful logins during business hours
Why it's wrong here
Successful business-hours logins are routine authentication events, not exfiltration signals; they show access, not data movement. This indicator belongs in a baseline of normal behaviour, where deviations from it would be flagged. Detecting exfiltration instead requires monitoring outbound volume, destination, or unusual transfer timing.
- ✓
Large outbound data transfers to an external IP
Why this is correct
Exfiltration requires data leaving the network, so unusually large outbound transfers to an external IP directly indicate possible data theft. Volume and destination are the measurable network-flow characteristics that distinguish exfiltration from normal egress traffic.
- ✓
A user connecting to a known command-and-control server
Why this is correct
Contact with a known command-and-control server indicates an established attacker channel, a hallmark of compromised hosts staging or exfiltrating data. This destination-based indicator complements volume analysis by revealing the adversary infrastructure receiving the stolen information.
- ✗
Multiple failed login attempts
Why it's wrong here
Multiple failed login attempts indicate brute-force or credential-stuffing activity against authentication, not outbound data movement. It tempts because failed logins are a classic SIEM alert, but exfiltration detection requires indicators such as anomalous outbound transfer volumes or unusual destination addresses, not authentication failures.
- ✗
Elevated CPU usage on a database server
Why it's wrong here
Elevated CPU usage on a database server may reflect legitimate query load, indexing, or maintenance, and does not itself demonstrate data leaving the environment. It tempts because resource spikes often accompany suspicious activity, but exfiltration indicators concern outbound data volume and destinations, not processor utilisation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.