You must configure a working C2 listener, explain how jitter and beacon interval shape traffic, and choose resilient persistence methods. The single most important thing: know that DNS query and proxy logs are the highest-value detection sources, and that jitter exists to defeat timing-based beacon analysis.
Start practicing
Command and Control — choose a session length
Free · No account required
Domain overview
This domain covers establishing and maintaining covert channels between compromised hosts and attacker infrastructure, including beacon configuration, jitter, redirectors, and fallback channels. GPEN tests it through scenario questions on C2 frameworks like Metasploit and Cobalt Strike, asking you to configure listeners, interpret beacon parameters, choose resilient persistence methods, and identify which log sources reveal DNS or HTTP-based command and control.
Exam objectives
Configuring Metasploit handlers and Cobalt Strike listeners with correct payload, port, and profile settings
Interpreting beacon interval, jitter, and sleep parameters and their effect on traffic patterns
Using redirectors, domain fronting, and fallback channels to survive infrastructure takedowns
Detecting C2 via DNS query logs, proxy logs, and NetFlow or Zeek connection records
Confusing beacon interval with jitter: interval sets base sleep time, jitter randomizes it as a percentage to avoid predictable timing
Assuming a single C2 server is resilient; takedown resistance requires redirectors, fallback channels, or domain rotation
Overlooking DNS as a C2 channel because payloads are small; DNS query logs are the primary detection source for DNS tunneling
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?
2Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?
3Which term best describes the stage of a cyberattack where a compromised host signals a remote server to request instructions or transmit stolen data?
4When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?
5Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?
6Which of the following is a classic characteristic of 'beaconing' behavior observed in C2 traffic?
7What is the primary risk of using 'Domain Fronting' in a C2 architecture during a penetration test?
8Why do many C2 frameworks include a 'sleep' command that can be configured by the operator?
9When evaluating the security of an organization's C2 detection capabilities, which log source is the most valuable for detecting DNS-based C2?
10An attacker uses a 'redirector' in their C2 infrastructure. What is the primary purpose of this architectural component?
11Which of the following is the most effective way to detect C2 beacons that use jitter and randomized timing?
12During an internal penetration test, you have compromised a Windows workstation and need to establish a covert channel that will survive network address translation and filtering. You decide to use the Domain Name System (DNS) TXT record for command and control. Which tool should you use to create a DNS tunnel that encapsulates IP traffic over DNS queries and responses?
13During an authorized penetration test, you have established a C2 session using a popular framework. Your goal is to maintain persistent access to a compromised Windows host even after the user logs off or the system reboots. You decide to use a service-based persistence mechanism. Which of the following commands, when executed on the compromised host, would create a new Windows service that runs your payload at startup?
14You are performing an authorized penetration test and have established a C2 channel using HTTPS. To evade network detection, you configure your C2 beacon to use domain fronting. Which of the following best describes how domain fronting masks the true destination of your C2 traffic?
15You are using Cobalt Strike in an authorized penetration test. The target network uses a next-generation firewall that performs SSL inspection and blocks self-signed certificates. You need to configure your HTTPS beacon to blend in with legitimate traffic and avoid detection. (Choose two.)
16You are configuring a C2 listener to use a malleable profile to blend in with legitimate traffic. Which two of the following are key benefits of using a malleable C2 profile in a penetration test? (Choose two.)
17A penetration tester has compromised a host in a restricted network that only allows outbound DNS queries to a specific internal resolver. The tester needs to establish a command and control channel that can traverse this restriction. Which C2 technique is most appropriate?
18You are configuring a Cobalt Strike beacon for a penetration test. The client's security team monitors for periodic beaconing patterns. You want to reduce the chance of detection by network behavior analysis. Which beacon setting should you adjust?
19During an authorized penetration test, you compromise a Windows host in a restricted network segment that only permits outbound DNS (UDP 53) to an internal resolver. You need to establish a command-and-control channel that can survive reboots and provide interactive shell access while blending with normal DNS traffic. Which of the following is the MOST appropriate technique to achieve this?
20During a penetration test, you have established a C2 channel using a domain fronting technique with a CDN. The target organization's proxy logs show connections to a high-reputation domain, but the actual C2 traffic is destined for your backend server. Which component is essential for this setup to function?
21You are conducting a penetration test against a target that employs a next-generation firewall (NGFW) with SSL inspection. Your C2 channel uses a custom protocol over TCP port 8443 with a self-signed certificate. The NGFW is blocking your traffic. You need to modify your C2 configuration to evade detection while maintaining command and control. Which of the following changes is MOST likely to succeed?
22You are designing a resilient command-and-control (C2) infrastructure for an authorized penetration test. The client's network has strict egress filtering and monitors for anomalous traffic. You need to ensure that your C2 channel can survive the takedown of a single server and adapt to changing network conditions. Which two of the following techniques should you implement? (Choose two.)
23You are setting up a C2 infrastructure for a penetration test. To protect the backend C2 server from direct exposure, you deploy a redirector. Which of the following best describes the primary function of a redirector in this context?
24You are using a C2 framework that supports malleable C2 profiles. Your current profile uses a default HTTP GET beacon with a fixed User-Agent and a URI of /submit.php. The target's network monitoring has flagged this traffic as suspicious. You need to modify the profile to better blend with legitimate traffic. Which of the following changes is the MOST effective for evading network-based detection?
You must configure a working C2 listener, explain how jitter and beacon interval shape traffic, and choose resilient persistence methods. The single most important thing: know that DNS query and proxy logs are the highest-value detection sources, and that jitter exists to defeat timing-based beacon analysis.
The Courseiva GPEN question bank contains 24 questions in the Command and Control domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Command and Control domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included