ネットワークアクティビティのレビューを完了した後。脅威ハンティング チームは、メール クライアント経由で社外の電子メール アドレスにアウトバウンド電子メールを毎日送信するネットワーク上のデバイスを発見します。
午後 10:00 に発生する可能性のあるものは次のうちどれですか?
正解:D
Data exfiltration is the theft or unauthorized transfer or movement of data from a device or network. It can occur as part of an automated attack or manually, on-site or through an internet connection, and involve various methods. It can affect personal or corporate data, such as sensitive or confidential information. Data exfiltration can be prevented or detected by using compression, encryption, authentication, authorization, and other controls1 The network activity shows that a device on the network is sending an outbound email via a mail client to a non-company email address daily at 10:00 p.m. This could indicate that the device is compromised by malware or an insider threat, and that the email is used to exfiltrate data from the network to an external party.
The email could contain attachments, links, or hidden data that contain the stolen information. The timing of the email could be designed to avoid detection by normal network monitoring or security systems.