A security analyst received a tip that sensitive proprietary information was leaked to the public. The analyst is reviewing the PCAP and notices traffic between an internal server and an external host that includes the following: ... 12:47:22.327233 PPPoE [ses 0x8122] IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto IPv6 (41), length 331) 10.5.1.1 > 52.165.16.154: IP6 (hlim E3, next-header TCP (6) paylcad length: 271) 2001:67c:2158:a019::ace.53104 > 2001:0:5ef5:79fd:380c:dddd:a601:24fa.13788: Flags [P.], cksum 0xd7ee (correct), seq 97:348, ack 102, win 16444, length 251 ... Which of the following was most likely used to exfiltrate the data?
Choose an answer
Tap an option to check your answer.
Correct answer: Encapsulation.
Why this is the answer
The PCAP shows an IPv6 packet encapsulated within an IPv4 packet (indicated by proto IPv6 (41) and IP6). This is a common technique for tunneling IPv6 traffic over an IPv4 network, but it can also be used for data exfiltration by hiding sensitive data within the encapsulated payload. MAC address spoofing changes the source MAC address but doesn't inherently exfiltrate data. Steganography hides data within innocent-looking files, not directly in network packet headers in this manner. Broken encryption would make data readable if intercepted but doesn't describe the exfiltration method itself. Sniffing via an on-path position is a method of capturing traffic, not exfiltrating data.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed