300-215 exam dumps

300-215 practice question 186 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 186

Single answer

You are investigating a potential data exfiltration incident in your organization. Using Cisco NetFlow and Wireshark, you identify unusual outbound traffic to an unfamiliar external IP address on port 443. The external IP has been flagged in threat intelligence feeds. Upon analyzing the traffic in Wireshark, you observe TLS-encrypted sessions but notice a significantly high volume of small-sized packets being sent. What is the most likely interpretation of this behavior?

  1. A

    The traffic is part of legitimate HTTPS communication.

  2. B

    The traffic indicates a potential Command and Control (C2) communication.

  3. C

    The traffic suggests a Distributed Denial-of-Service (DDoS) attack.

  4. D

    The traffic indicates a potential data exfiltration attempt.

Show answer and explanation

Correct answer: D

Explanation

This scenario describes characteristics commonly associated with data exfiltration. Threat actors often use encrypted channels, such as HTTPS on port 443, to disguise malicious activity. The unusual outbound traffic, flagged IP, and high volume of small-sized packets are strong indicators that data exfiltration is taking place. Network monitoring tools like NetFlow can help identify such anomalies, while Wireshark's packet analysis can confirm the nature of the traffic.

  • A. Incorrect.

    This is unlikely because legitimate HTTPS traffic typically involves varied packet sizes, not a consistent high volume of small packets.

  • B. Incorrect.

    While C2 communication could involve encrypted traffic, it generally exhibits sporadic and low-bandwidth connections, not a high volume of small packets.

  • C. Incorrect.

    DDoS attacks typically involve a high volume of traffic targeting a specific victim, not outbound traffic to an unfamiliar IP.

  • D. Correct.

    A high volume of small-sized packets over encrypted channels to an unfamiliar IP on port 443 is a common indicator of data exfiltration, as the attacker may be breaking data into small chunks to evade detection.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam