An in-house penetration tester has been asked to evade a new DLP system. The tester plans to exfiltrate data through steganography. Discovery of which of the following would help catch the tester in the act?

Last Updated on August 14, 2021 by Admin

An in-house penetration tester has been asked to evade a new DLP system. The tester plans to exfiltrate data through steganography.

Discovery of which of the following would help catch the tester in the act?

  • Abnormally high numbers of outgoing instant messages that contain obfuscated text
  • Large-capacity USB drives on the tester’s desk with encrypted zip files
  • Outgoing emails containing unusually large image files
  • Unusual SFTP connections to a consumer IP address