A company suffered a critical incident where 30GB of data was exfiltrated from the corporate network. Which of the following actions is the most efficient way to identify where the system data was exfiltrated from and what location the attacker sent the data to?
Choose an answer
Tap an option to check your answer.
Correct answer: Analyze firewall and network logs for large amounts of outbound traffic to external IP addresses or domains..
Why this is the answer
Analyzing firewall and network logs is the most efficient way because they directly record outbound connections, including destination IP addresses and data volume. This allows you to pinpoint the source system within your network and the external location where the 30GB of data was sent. IPS/IDS logs primarily focus on detecting intrusions and reconnaissance, not necessarily the exfiltration itself or the destination. Endpoint/application logs might show file-sharing activity but won't definitively link it to the specific 30GB exfiltration or its external destination. Vulnerability scan reports identify potential weaknesses, not actual data exfiltration events or their pathways.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed