Proxy logs show an analyst workstation sending 18 GB over HTTPS to a personal file-sharing site at 02:15. The user says it is a scheduled cloud backup. Which next step best confirms whether this is exfiltration rather than normal backup activity?
Select an answer to reveal the explanation.
Short Explanation
Think of HTTPS uploads as a courier dropping off boxes: encryption hides the contents, not the handoff. Check the endpoint logs to see whether a backup agent is doing the work or a person is dragging files into a browser. That is how you separate routine cloud sync from a quiet exit door.
Full Explanation
Exfiltration triage depends on matching network behavior to endpoint provenance. Large HTTPS uploads to a consumer file-sharing domain can be encrypted, but the decisive evidence is whether the process and source files correspond to an authorized backup agent or to user-driven collection. Endpoint detection and response telemetry can show the executable, parent process, file paths, and time correlation, allowing the analyst to distinguish scheduled backup traffic from manual staging and upload before containment decisions are made. Immediate blocking and credential reset may be prudent after confirmation, but doing them first can destroy the evidence chain and does not itself prove exfiltration. Treating the traffic as benign solely because it uses HTTPS and cloud storage ignores that encrypted transport is commonly abused to hide data theft and policy violations. A vulnerability scan assesses weaknesses, not recent data movement, so it cannot establish whether files were collected or uploaded. Exam caveat: CompTIA expects the analyst to validate telemetry and preserve evidence before taking disruptive containment actions. Operational check: Pivot from the proxy session to the endpoint process tree and file-access events, then export the correlation timeline before isolating the host.