ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 128 - CS0-003 discussion

Report
Export

After completing a review of network activity. the threat hunting team discovers a device on the network that sends an outbound email via a mail client to a non-company email address daily at 10:00 p.m. Which of the following is potentially occurring?

A.
Irregular peer-to-peer communication
Answers
A.
Irregular peer-to-peer communication
B.
Rogue device on the network
Answers
B.
Rogue device on the network
C.
Abnormal OS process behavior
Answers
C.
Abnormal OS process behavior
D.
Data exfiltration
Answers
D.
Data exfiltration
Suggested answer: D

Explanation:

Data exfiltration is the theft or unauthorized transfer or movement of data from a device or network. It can occur as part of an automated attack or manually, on-site or through an internet connection, and involve various methods. It can affect personal or corporate data, such as sensitive or confidential information.Data exfiltration can be prevented or detected by using compression, encryption, authentication, authorization, and other controls1

The network activity shows that a device on the network is sending an outbound email via a mail client to a non-company email address daily at 10:00 p.m. This could indicate that the device is compromised by malware or an insider threat, and that the email is used to exfiltrate data from the network to an external party. The email could contain attachments, links, or hidden data that contain the stolen information. The timing of the email could be designed to avoid detection by normal network monitoring or security systems.

asked 02/10/2024
Jose M Rivera Vega
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first