CySA+ CS0-001 – Q. 408


An analyst identifies multiple instances of node-to-node communication between several endpoints within the network and a user machine at the IP address This user machine at the IP address is also identified as initiating outbound communication during atypical business hours with several IP addresses that have recently appeared on threat feeds.
Which of the following can be inferred from this activity?

A. is infected with ransomware.
B. is not routable address space.
C. is a rogue endpoint.
D. is exfiltrating data.