A systems administrator is reviewing the VPN logs and notices that during non-working hours a user is accessing the company file server and information is being transferred to a suspicious IP address. Which of the following threats is most likely occurring?
Choose an answer
Tap an option to check your answer.
Correct answer: Data exfiltration.
Why this is the answer
Data exfiltration is the unauthorized transfer of data from a computer or network. In this scenario, a user accessing the company file server during non-working hours and transferring information to a suspicious IP address strongly indicates data exfiltration. The intent is to steal sensitive information. Typosquatting involves registering domain names similar to legitimate ones to trick users, which is unrelated to the described activity. Root or trust is not a recognized threat in this context; "root of trust" refers to a foundational component in a security system. Blackmail involves coercing someone through threats, typically after data has been exfiltrated or compromised, but the act of transferring data itself is exfiltration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed