100-160 Question 19
Single answerA small company's IT administrator discovers unusual outbound traffic from one of their servers, which is also experiencing slower-than-usual performance. Upon investigation, they find that sensitive data has been exfiltrated to an unknown external IP address. Which type of threat is most likely responsible for this incident?
- A
Phishing attack
- B
Denial-of-Service (DoS) attack
- C
Ransomware
- D
Advanced Persistent Threat (APT)
Show answer and explanation
Correct answer: D
Explanation
The scenario describes a situation where an attacker has gained unauthorized access to a server, maintained persistence, and exfiltrated sensitive data. This is characteristic of an Advanced Persistent Threat (APT), which involves targeted, long-term attacks aimed at stealing sensitive information. The other options do not align with the described behavior of the threat.
- A. Incorrect.
A phishing attack typically involves tricking individuals into sharing sensitive information, such as login credentials, via deceptive emails or websites. While phishing could be a precursor to this scenario, it does not directly explain the ongoing exfiltration of data and server compromise described.
- B. Incorrect.
A Denial-of-Service (DoS) attack aims to overwhelm a system or network, rendering it unavailable to legitimate users. This does not align with the symptoms described, such as data exfiltration and slower server performance.
- C. Incorrect.
Ransomware encrypts files and demands payment for decryption. While it can disrupt server operations, it does not involve covert data exfiltration to an external IP address.
- D. Correct.
An Advanced Persistent Threat (APT) is a prolonged and targeted attack where cybercriminals infiltrate a network to steal sensitive data while remaining undetected. This matches the described situation, as the attacker has maintained access to the server and exfiltrated data to an unknown IP.