20+ practice questions focused on Command and Control — one of the most tested topics on the GIAC Penetration Tester exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Command and Control PracticeWhich THREE techniques are commonly used by attackers to hide C2 traffic within legitimate network protocols?
Explanation: Attackers disguise C2 traffic to blend in with normal organizational traffic, reducing the probability of detection by security teams. By leveraging protocols that are already allowed through firewalls, they ensure reliable communication while remaining stealthy. Understanding these masking techniques allows testers to develop more effective detection rules, focusing on content inspection and behavioral analysis rather than simple port blocking, which is often bypassed by these sophisticated methods.
During an authorized penetration test, you successfully establish an interactive command and control shell via DNS tunneling. However, you notice that large data exfiltration queries are frequently failing or timing out due to upstream DNS server payload restrictions and strict rate limiting. Which action should you take to optimize reliability while maintaining covert persistence?
Explanation: Switching to a stateful protocol like HTTPS or utilizing DNS direct-server communication via a designated authoritative nameserver bypasses recursive resolver payload ceilings. This technique ensures reliable fragmentation and chunking of large files without triggering anomalous query rates or dropping packets at intermediary caching servers during penetration testing operations.
You are conducting a penetration test and have established a C2 channel using the Metasploit Framework's Meterpreter payload. You need to maintain persistence on the compromised Windows host while ensuring that the C2 communication survives reboots and user logoffs. Which two techniques can you use with Meterpreter to achieve this? (Choose two.)
Explanation: The two techniques that provide persistence for a Meterpreter session are using the 'persistence' module to create a registry key and using 'schtasks' to create a scheduled task. Both ensure that the payload runs automatically at startup or logon, re-establishing the C2 channel. Migration, RDP, and keylogging do not provide automatic reconnection after a reboot.
During an authorized penetration test, you have established a Meterpreter session to a Windows 10 target over TCP port 443. The client's egress firewall begins inspecting TLS certificates and blocking self-signed certificates. Your session dies. You need a new payload that can survive this inspection while still using port 443. Which Metasploit payload is best suited?
Explanation: The firewall blocks self-signed certificates. Using reverse_https with a valid certificate makes the TLS handshake appear legitimate, allowing the payload to traverse the firewall on port 443. Other options either still use self-signed certificates or abandon TLS entirely, which may trigger other blocks. This approach mimics legitimate HTTPS traffic, a common technique in penetration testing.
During a penetration test, you have compromised a host in a restricted network that only allows outbound DNS traffic. You need to establish a C2 channel. Which of the following techniques would be most effective for maintaining a reliable, low-bandwidth C2 channel over DNS?
Explanation: DNS TXT records are the most effective for DNS-based C2 because they can carry arbitrary data and are often allowed through firewalls. Encoding command output in TXT queries or responses enables bidirectional communication. Other DNS record types like A, PTR, or MX are limited in their ability to carry data or are not typically allowed for arbitrary use, making them less suitable for a reliable C2 channel.
+15 more Command and Control questions available
Practice all Command and Control questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Command and Control. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Command and Control questions on the GPEN frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Command and Control is tested as part of the GIAC Penetration Tester blueprint. Practicing with targeted Command and Control questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GPEN practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Command and Control is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Command and Control practice session with instant scoring and detailed explanations.
Start Command and Control Practice →