GCIH Network and Log Investigations Practice Question
An incident handler is analyzing a packet capture to identify command-and-control (C2) communication. Which two characteristics are most indicative of C2 traffic? (Choose two.)
⚠ Common exam trap
The trap here is focusing on port numbers or data volume alone, but C2 can use standard ports like 80 or 443, and exfiltration may be separate; the key is the regularity and encoding patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Periodic connections to the same external IP address at regular intervals
Beaconing and DNS tunneling are two strong indicators of C2 communication. Beaconing involves regular, periodic connections that malware uses to check in with its controller. DNS tunneling encodes data in DNS queries, often using high entropy subdomains to carry commands or exfiltrate data. Other characteristics like non-standard ports or large transfers may be present but are not as specific to C2, as they can occur in legitimate traffic. Combining multiple indicators increases confidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use of HTTP GET requests with long, random-looking URI parameters
Why it's wrong here
While some C2 channels use HTTP with encoded parameters, this is not as definitive as beaconing. Legitimate applications may also use long, random-looking parameters for session IDs or tracking. Without additional context such as periodic timing or known malicious IPs, this characteristic alone is not a strong indicator of C2.
- ✗
Large outbound data transfers to an external IP address during non-business hours
Why it's wrong here
Large outbound transfers can indicate data exfiltration, which is often a goal of C2, but they are not specific to C2 communication itself. C2 traffic is typically small and periodic for command and control, while exfiltration may be a separate phase. Non-business hours transfers could also be legitimate backups, so this is not a reliable indicator of C2.
- ✓
Periodic connections to the same external IP address at regular intervals
Why this is correct
Periodic connections at regular intervals, often called beaconing, are a hallmark of C2 communication because malware typically checks in with its controller at set times to receive commands or exfiltrate data. This pattern is distinct from normal user traffic, which is more random. The regularity can be configured by the attacker to blend in, but it remains a strong indicator.
- ✗
Connections to an external IP address on a non-standard port that is not associated with any known service
Why it's wrong here
While attackers may use non-standard ports to evade detection, many legitimate applications also use non-standard ports. This characteristic alone is not a strong indicator of C2 because it lacks behavioral context. For example, a custom application might use a high port for legitimate communication. Without other signs like beaconing or known malicious IPs, it is inconclusive.
- ✓
Repeated DNS queries for a domain with a high entropy subdomain
Why this is correct
High entropy subdomains in DNS queries are often used in DNS tunneling for C2, where data is encoded in the subdomain. Repeated queries to such domains can indicate a compromised host communicating with a C2 server via DNS. This method is stealthy because DNS is often allowed. The high entropy distinguishes it from normal domain names, which are typically pronounceable.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.