Courseiva

CCNA Detecting Exploitation and Covert Communication Tools Questions

14 questions · Detecting Exploitation and Covert Communication Tools · All types, answers revealed

1
MCQmedium

An incident responder reviews a packet capture from a compromised Windows workstation and notices periodic outbound DNS queries for random-looking subdomains such as 'a8f3c9e1.badguy.example'. Each query is followed by a TXT record response containing a short Base64 string. What technique is being used?

A.Fast flux DNS
B.DNS tunneling for command and control
C.DNS cache poisoning
D.Domain generation algorithm (DGA) beaconing
AnswerB

The random subdomains and TXT responses carrying Base64 data are characteristic of DNS tunneling, where an attacker encodes C2 instructions or exfiltrated data within DNS queries and responses. The use of TXT records to return payloads further confirms this, as legitimate DNS TXT records rarely contain such encoded data in this pattern.

Why this answer

The correct answer is DNS tunneling for command and control. Random subdomains combined with TXT records carrying Base64 data indicate that the attacker is using DNS as a covert channel to send commands or exfiltrate data. Legitimate DNS traffic rarely exhibits such encoded payloads, making this a strong indicator of compromise.

Exam trap

The trap here is assuming that any random-looking DNS query is DGA activity, when the presence of encoded TXT responses specifically points to DNS tunneling.

2
Multi-Selecthard

Which THREE actions are effective at identifying hidden 'living-off-the-land' (LotL) binary usage in a compromised system?

Select 3 answers
A.Reviewing command-line argument logs for suspicious flags.
B.Monitoring for unexpected network connections from system tools.
C.Scanning the disk for all instances of binary files.
D.Auditing process lineage to identify suspicious parent-child relations.
E.Restricting all user permissions to local system accounts.
AnswersA, B, D

LotL binaries often require specific, unusual flags to perform malicious tasks like downloading content or executing remote code. Logging and analyzing these command-line arguments is the most effective way to detect misuse of trusted binaries, as the tool itself is legitimate but the parameters reveal the attacker's intent.

Why this answer

LotL attacks use legitimate tools like WMI, PowerShell, and certutil to perform malicious actions, making them difficult to detect. Since the binaries are trusted, defenders must look for suspicious execution contexts, unusual parameters, or non-standard parent processes. This is critical because attackers use these techniques to bypass signature-based endpoint protection, requiring behavioral analysis to uncover the unauthorized activity within the noise of standard system management tasks.

Exam trap

Candidates often try to block the binaries themselves, which is impossible because LotL attacks use essential system tools that are required for normal operating system functionality.

3
MCQhard

When investigating a suspected malicious process in memory, why is it critical to analyze the 'Parent Process ID' (PPID) in conjunction with the process's execution path?

A.To identify which user account initiated the malicious activity.
B.To detect anomalies in process lineage and execution context.
C.To determine the file creation date on the disk.
D.To ensure the process is running with administrative privileges.
AnswerB

Analyzing the parent process is essential to determine if a process was spawned by an expected entity. Anomalous process lineages, such as a browser spawning a command shell, are strong indicators of exploitation. This context helps differentiate between normal system operations and malicious activity, enabling effective incident detection and root-cause analysis.

Why this answer

PPID analysis reveals the execution chain, which is often a major red flag for malicious activity. For example, a web server process spawning a shell is highly suspicious. Understanding these relationships allows incident handlers to detect process hollowing and injection attacks.

This context is essential because it distinguishes between legitimate system operations and adversarial techniques designed to blend into the system's normal process hierarchy.

Exam trap

Candidates often focus solely on the process name, ignoring the parent-child relationship, which allows attackers to hide malicious activity by masquerading as legitimate processes like 'svchost.exe' or 'explorer.exe'.

4
MCQmedium

Refer to the exhibit. An analyst observes this command output on a compromised server. What is the most likely intent of the attacker?

A.Listing available files for exfiltration.
B.Preparing for ransomware deployment by removing backups.
C.Escalating privileges to the SYSTEM account.
D.Cleaning up evidence of previous tool execution.
AnswerB

The deletion of volume shadow copies is a standard step for ransomware operators to prevent victims from restoring files without paying the ransom. By identifying this command early, an analyst can potentially stop the encryption process before the damage is done, demonstrating the effectiveness of proactive log monitoring.

Why this answer

Attackers use `vssadmin` to delete shadow copies, effectively disabling the system's ability to recover files after encryption by ransomware. Detecting this command is a high-fidelity signal of an active ransomware attack or a data destruction event. Incident responders must act immediately upon seeing this, as it indicates the adversary is cleaning up recovery options before deploying their final payload or after exfiltration is complete.

Exam trap

Candidates often mistake this for simple system maintenance or administrative backup rotation, failing to recognize that deleting shadow copies is a hallmark of ransomware preparation intended to prevent recovery.

5
MCQmedium

During an incident response engagement, you observe that a compromised Windows workstation periodically sends DNS queries for subdomains of 'sync.update-service.com', such as 'a1b2c3.sync.update-service.com'. The queries occur at irregular intervals, and the responses contain TXT records with long, high-entropy strings. The domain is not associated with any known legitimate service. Which technique is the adversary most likely using?

A.Fast flux DNS to evade blocklists
B.Domain fronting to hide C2 traffic
C.DNS tunneling for command and control
D.DNS cache poisoning to redirect traffic
AnswerC

The use of TXT records with high-entropy data and irregular query timing to a suspicious domain is characteristic of DNS tunneling, where data is encoded in DNS queries and responses to establish a covert channel. The subdomain labels likely carry encoded commands or exfiltrated data, and the TXT responses deliver instructions or acknowledgments.

Why this answer

The adversary is using DNS tunneling to encapsulate command and control data within DNS queries and responses. The high-entropy TXT records and irregular subdomain queries indicate encoded data being sent to and from the attacker's authoritative DNS server. This technique bypasses many network controls because DNS is often allowed outbound.

Exam trap

The trap here is assuming any suspicious DNS traffic is domain fronting or fast flux, when the presence of TXT records and encoded subdomains specifically points to DNS tunneling.

6
MCQmedium

During incident response, you observe that a compromised host is sending ICMP echo request packets with a payload size of 1000 bytes to an external IP. The payload appears to contain non-printable characters. What is the most likely explanation?

A.The host is experiencing a network loop.
B.The host is infected with a worm that scans for vulnerabilities.
C.The host is performing a ping flood attack.
D.The host is using ICMP tunneling for covert communication.
AnswerD

ICMP tunneling hides data within ICMP echo request and reply packets. The large, non-printable payload is a strong indicator that the attacker is using ICMP as a covert channel to send commands or exfiltrate data, often to bypass firewalls that allow ICMP.

Why this answer

The correct answer is ICMP tunneling for covert communication. Large ICMP packets with non-printable payloads sent to a single external IP are a classic sign of ICMP tunneling, where data is hidden in the payload to evade detection.

Exam trap

The trap here is assuming that any large ICMP packet is a ping flood, when the payload content and destination specificity indicate tunneling.

7
MCQmedium

During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the payload field. Which specific command-line utility should you look for in the process execution history to identify the tool responsible for generating this traffic?

A.ping
B.traceroute
C.hping3
D.tcpdump
AnswerC

Hping3 enables system administrators and security testers to assemble and send custom ICMP, TCP, and UDP packets. Threat actors leverage its advanced packet crafting capabilities to smuggle encoded internal data through restricted network perimeters via covert channels.

Why this answer

Hping3 is a popular packet generator and analyzer for TCP/IP that supports crafting arbitrary ICMP packets with custom payload data. Attackers frequently leverage hping3 or similar custom scripting tools to exfiltrate data through covert channels when standard protocols are blocked by perimeter firewalls, making process history analysis critical for detection.

Exam trap

Candidates often suspect standard diagnostic tools like ping or traceroute, failing to realize that native administrative binaries lack the flexible payload manipulation required for covert data exfiltration without modification.

8
MCQmedium

An analyst discovers a malicious DLL file in a system directory. What is the most effective way to identify which process loaded this DLL into memory?

A.Search the file system for other files with similar names.
B.Examine the Windows Event Logs for file creation events.
C.Use memory forensics tools to inspect loaded modules per process.
D.Check the registry for new service installation entries.
AnswerC

Memory forensics tools like Volatility or Rekall can enumerate the loaded DLLs for every running process. This is the only reliable way to confirm which process is actively utilizing the malicious library, allowing the investigator to link the malicious file to the specific process being exploited or controlled.

Why this answer

Identifying the process that loaded a malicious DLL is fundamental for understanding the scope of the compromise. Memory forensic tools can map loaded modules to specific process IDs (PIDs). This is critical because it allows the handler to identify whether the DLL is being used for process injection, persistence, or credential theft, providing the necessary evidence to isolate and remediate the affected processes immediately.

Exam trap

Candidates often suggest scanning the file system or checking file hashes, which fails to reveal how the malicious DLL was injected or which specific process is currently utilizing it in memory.

9
MCQmedium

An adversary uses PowerShell to establish a reverse shell. The command includes the '-EncodedCommand' flag with a long Base64 string. What is the most effective way to detect this activity without relying on static command signatures?

A.Block all outbound connections originating from PowerShell processes.
B.Enable PowerShell Script Block Logging to capture de-obfuscated code.
C.Monitor for any usage of the 'powershell.exe' process in logs.
D.Perform string analysis on all files in the system directories.
AnswerB

Script Block Logging captures the final, de-obfuscated script content that is actually executed by the PowerShell engine. This bypasses the Base64 encoding completely, giving analysts visibility into the raw commands. This is the industry-standard method for detecting and investigating malicious PowerShell usage in enterprise environments today.

Why this answer

Static signatures fail against randomized Base64 encoding. Behavioral detection, specifically script block logging, captures the de-obfuscated code before execution. This is essential for incident handlers because attackers frequently use obfuscation to bypass simple keyword filters.

Script block logging provides the exact command executed in memory, allowing for accurate analysis of the intent regardless of the obfuscation technique employed by the attacker.

Exam trap

Candidates often search for static Base64 strings, which is ineffective because attackers can easily randomize encoding, rendering static signatures useless against modern obfuscated PowerShell payloads.

10
MCQeasy

A security analyst notices that a user's workstation is communicating with an external IP address on port 443, but the traffic is not TLS. Instead, the packets contain a custom protocol with a fixed header. The connection is persistent and occurs every night at 2 AM. Which type of covert communication is this most likely?

A.A misconfigured application using the wrong port
B.A legitimate software update service
C.A denial-of-service attack
D.A covert channel using a non-standard protocol over a common port
AnswerD

The traffic uses port 443, which is typically associated with HTTPS, but the payload is not TLS. Instead, it uses a custom protocol. This is a classic covert channel technique: hiding malicious communication on a commonly allowed port to bypass firewalls and evade detection. The persistent, scheduled nature also suggests a beaconing implant.

Why this answer

The correct answer is a covert channel using a non-standard protocol over a common port. Attackers often use ports like 443 to blend in with normal traffic, but they may implement their own protocol instead of TLS to avoid detection or because it's simpler. The persistent, scheduled connection suggests a beaconing implant that checks in with a C2 server.

This technique can evade firewalls that allow outbound 443 traffic.

Exam trap

The trap here is assuming that traffic on port 443 is always TLS; attackers frequently use common ports with custom protocols to bypass security controls.

11
MCQmedium

An analyst detects an outbound connection using a non-standard port that exhibits high-frequency 'jitter'. Which technique best characterizes the nature of this communication?

A.Data exfiltration using high-speed burst transfers.
B.Command and control beaconing with evasion techniques.
C.Standard web browsing activity during lunch hours.
D.Network congestion caused by heavy application traffic.
AnswerB

Jitter is a common C2 evasion technique used to defeat detection systems that look for perfectly periodic connections. By adding randomness to the delay between beacons, the adversary masks the automated nature of the communication. This indicates a high level of sophistication and necessitates heuristic-based detection methodologies.

Why this answer

Jitter is the deliberate randomization of time intervals between network beacons to evade detection by algorithms looking for fixed-cadence heartbeats. By introducing this variability, attackers make their C2 traffic appear more 'human' or natural. Recognizing this technique is vital for incident handlers because it highlights the sophistication of the C2 infrastructure, requiring advanced statistical analysis beyond simple threshold-based alerts to identify the underlying automated pattern.

Exam trap

Candidates often misidentify jitter as network congestion or packet loss, failing to realize it is a deliberate, calculated technique used by C2 frameworks to mask automated communication patterns.

12
MCQhard

During an incident response engagement, an analyst reviews network flow records and notices a compromised Linux server making outbound connections to an external host. Each connection lasts exactly 45 seconds, transfers roughly 2 KB, and then terminates; a new connection begins 15 seconds later. The destination IP changes every few hours among a pool of addresses in the same /24. The payload is fully encrypted and no standard application protocol headers are visible. Which technique is the attacker MOST likely using to maintain command-and-control while evading detection?

A.Fast-flux DNS with round-robin A records
B.Peer-to-peer botnet communication using a distributed hash table
C.Beaconing over a covert channel with rotating infrastructure
D.Domain fronting through a content delivery network
AnswerC

The fixed 45-second connection duration, consistent 2 KB payload, 15-second gap, and periodic rotation of destination IPs within a /24 are classic indicators of automated beaconing used by command-and-control implants. Encrypted payloads with no standard protocol headers suggest a custom covert channel. Rotating infrastructure helps evade IP-based blocklists while the steady cadence maintains check-in with the operator.

Why this answer

The rigid timing, consistent small payload, and rotating destination IPs within a narrow range strongly indicate an automated beacon from a covert channel implant. Such implants often use custom encryption and non-standard protocols to blend in, while periodically changing C2 addresses to defeat static blocklists. Recognizing beaconing cadence and infrastructure rotation is essential for identifying stealthy command-and-control during incident response.

Exam trap

The trap here is assuming any encrypted outbound traffic must be domain fronting or fast-flux, when the deterministic beaconing cadence and small fixed payloads are the real signature of a covert channel.

13
MCQmedium

During an incident response engagement on a Linux server, you discover an attacker has established covert command and control using a custom backdoor communicating over raw ICMP sockets. Which network analysis method provides the most reliable detection mechanism for this specific covert channel regardless of packet payload obfuscation?

A.Scanning all active network interfaces for unauthorized listening TCP ports bound to high-numbered ports.
B.Analyzing ICMP packet frequency, inter-arrival timing anomalies, and payload size distributions across network flows.
C.Reviewing traditional stateful firewall drop logs for blocked SYN packets originating from internal server zones.
D.Inspecting standard application layer web server access logs for anomalous HTTP POST request parameter values.
AnswerB

Raw ICMP tunnelling hides commands inside payloads, so signature or content inspection fails once obfuscated. Statistical analysis of packet frequency, inter-arrival timing and payload size distributions exposes the anomalous traffic pattern inherent to the covert channel, regardless of payload encoding.

Why this answer

Monitoring packet frequency and timing anomalies identifies ICMP tunneling because legitimate diagnostic tools like ping operate at steady, predictable intervals. Attackers forcing high-volume data transmissions create irregular burst patterns and anomalous payload sizes that standard baseline monitoring quickly highlights as suspicious behavior.

Effective incident handlers must look beyond simple signature detection when analyzing sophisticated tunneling techniques. Understanding foundational network protocols allows analysts to spot statistical deviations even when cryptographic encryption completely obscures the underlying application layer payload contents.

Exam trap

Candidates often assume that deep packet inspection or payload signatures are required to detect ICMP covert channels, completely overlooking statistical traffic profiling and timing anomaly detection methods.

14
MCQmedium

An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP address, which then executes 'whoami' and 'net user'. What is the most likely scenario?

A.A user struggling to remember their password.
B.Credential stuffing followed by automated reconnaissance.
C.A network administrator performing routine maintenance.
D.An automated script updating software versions.
AnswerB

The combination of multiple failed logins and immediate post-exploitation commands is a high-confidence indicator of account compromise. The attacker is mapping the environment to plan further movement. Detecting this progression allows the responder to isolate the compromised account before the adversary can escalate privileges or deploy additional malicious tools.

Why this answer

This sequence is a classic indicator of credential stuffing or password spraying followed by immediate reconnaissance. The shift from multiple failures (guessing) to a successful login (success) and then immediate discovery commands (post-exploitation) strongly suggests a compromised account being used by an adversary. This pattern is vital to detect early in the kill chain before the attacker moves laterally or achieves persistence within the network environment.

Exam trap

Candidates frequently misidentify the event as a simple brute force attack, missing the critical transition from authentication failures to immediate post-exploitation commands, which characterizes a successful account takeover.

Ready to test yourself?

Try a timed practice session using only Detecting Exploitation and Covert Communication Tools questions.