
CiscoCertified Network Professional Security
Domain 6Objective 5
6.5 Explain Exfiltration Techniques Such as DNS Tunneling, HTTPS, Email, FTP/SSH/SCP/SFTP, ICMP, Messenger, IRC, NTP, and Cloud Storage 350-701 Practice Questions (Page 2)
Part of the Network Access, Visibility, and Enforcement domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
9concepts
15%of the exam
Questions 6–10
- 6
A security team is investigating a data breach. They find that a user has been uploading files to a personal cloud storage account using HTTPS. The team wants to implement a control that prevents this exfiltration while still allowing legitimate business use of cloud storage. Which approach would BEST meet this requirement?
Select an answer first - 7
A security analyst is investigating a potential data exfiltration. The logs show a workstation maintaining a persistent connection to an IRC server. The analyst also sees DNS queries with long subdomains and ICMP echo requests with unusual payloads. The analyst needs to determine which technique is being used for the primary exfiltration channel. Which finding would MOST strongly indicate IRC exfiltration?
Select an answer first - 8
A security analyst notices a workstation sending a high volume of DNS queries to a single external domain that is not a known CDN or analytics service. The queries contain long, random-looking subdomain labels, and the responses are larger than typical DNS replies. The analyst also observes the workstation sending periodic ICMP echo requests to the same external IP with payloads that vary in size and content. Which two techniques are most likely being used together for data exfiltration?
Select an answer first - 9
How can cloud storage services be used to exfiltrate data?
Select an answer first - 10
A network administrator notices that a server is sending a large number of NTP requests to an external time server. The requests are more frequent than normal and the response packets are unusually large. The administrator suspects NTP abuse for exfiltration. Which characteristic of NTP makes it a viable exfiltration channel?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.