GCIH Network and Log Investigations Practice Question
An incident responder is analyzing a network capture to identify potential command-and-control (C2) communication. The capture shows a workstation making regular DNS queries to 'update.microsoft.com' every 60 seconds, each followed by a small HTTPS session to a different IP address. The HTTPS sessions use self-signed certificates and the User-Agent string is 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)'. Which TWO of the following indicators most strongly suggest malicious C2 activity? (Choose two.)
⚠ Common exam trap
The trap here is focusing on the regular intervals or multiple IPs, which can be legitimate, while ignoring the more definitive indicators like self-signed certificates and outdated User-Agent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The User-Agent string is outdated and inconsistent with the operating system.
The correct answers are that the HTTPS sessions use self-signed certificates and the User-Agent string is outdated and inconsistent. Self-signed certificates are a hallmark of malware C2 because they are not trusted and often used to avoid detection. An outdated User-Agent like MSIE 6.0 on a modern system suggests the traffic is generated by malware with hardcoded strings. Together, these strongly indicate malicious C2 activity, whereas the other options can be benign.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The DNS queries are for a legitimate domain but resolve to multiple IP addresses.
Why it's wrong here
Legitimate domains often resolve to multiple IPs for load balancing or CDN. While this could be suspicious if the IPs are known malicious, by itself it does not strongly indicate C2. The other factors like self-signed certificates and outdated User-Agent are more indicative. Thus, this is not one of the strongest indicators.
- ✗
The DNS queries occur at regular 60-second intervals.
Why it's wrong here
Regular intervals can indicate beaconing, but many legitimate applications also poll at fixed intervals (e.g., software updates, NTP). Without other indicators, this alone is not strong. In this scenario, the self-signed certificates and outdated User-Agent are more compelling. Thus, this is not one of the strongest indicators.
- ✗
The HTTPS sessions are to different IP addresses each time.
Why it's wrong here
Connecting to different IPs could be due to load balancing or fast-flux, but it is not inherently malicious. Many legitimate services use multiple IPs. The use of self-signed certificates and an outdated User-Agent are more direct indicators of C2. Therefore, this is not one of the strongest indicators.
- ✓
The User-Agent string is outdated and inconsistent with the operating system.
Why this is correct
An outdated User-Agent like 'MSIE 6.0' on a modern system is a red flag. Malware authors often hardcode old User-Agent strings, while legitimate applications use current ones. Inconsistency with the OS further suggests spoofing. This is a common indicator of C2 traffic, as it deviates from normal user behavior.
- ✓
The HTTPS sessions use self-signed certificates.
Why this is correct
Self-signed certificates are common in malware C2 because they are easy to generate and avoid the cost of legitimate certificates. They also allow the attacker to avoid detection by certificate authorities. In a corporate environment, legitimate services typically use trusted certificates. Therefore, self-signed certificates on outbound HTTPS are a strong indicator of malicious activity.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.