Question 1 of 30
In a corporate network, a security analyst is monitoring traffic patterns and notices an unusual spike in outbound traffic from a specific workstation during non-business hours. The workstation is known to have a file-sharing application installed. The analyst suspects that the traffic may be indicative of a data exfiltration attempt. To confirm this hypothesis, the analyst decides to analyze the traffic flow using a combination of packet capture and flow analysis tools. Which of the following patterns would most likely indicate malicious activity related to data exfiltration?
A consistent flow of large packets being sent to an external IP address that is not recognized by the organization, especially during off-peak hours.
A sporadic flow of small packets being sent to multiple internal IP addresses during business hours.
A steady stream of encrypted traffic to a known cloud storage service during business hours.
An increase in DNS queries from the workstation to various external domains throughout the day.

Preparing for CISCO 300-215 Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free