GPEN Command and Control Practice Question
An attacker uses a 'redirector' in their C2 infrastructure. What is the primary purpose of this architectural component?
⚠ Common exam trap
Candidates often assume a redirector is meant to increase connection speed or provide redundancy. They miss its primary tactical purpose: hiding the true location of the C2 server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To provide a layer of obfuscation for the C2 server.
Redirectors act as a layer of separation between the compromised host and the actual C2 server. They proxy the incoming beacon traffic to the real server, masking the location of the true command infrastructure. This protects the C2 server from being directly identified and blacklisted, as the traffic appears to originate from the redirector node. This is a critical component for maintaining a resilient and stealthy operational environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To increase the bandwidth of the C2 connection.
Why it's wrong here
Redirectors add latency and do not inherently increase bandwidth. In fact, they can decrease throughput due to the additional hop in the network path. Their purpose is strictly related to obfuscation and infrastructure protection, not performance optimization or data transfer speed improvements for the C2 channel.
- ✓
To provide a layer of obfuscation for the C2 server.
Why this is correct
Redirectors hide the true IP address of the C2 server by serving as a proxy. If a redirector is identified and blocked, the attacker can quickly pivot to a new redirector while the primary C2 server remains safely tucked away, ensuring the core infrastructure stays operational.
- ✗
To translate commands into local system calls.
Why it's wrong here
Command translation happens on the target system by the malware agent itself, not by a redirector. The redirector is simply a network node that forwards packets; it does not perform any processing or interpretation of the C2 traffic, nor does it interact with the target's operating system.
- ✗
To manage the encryption keys for the C2 channel.
Why it's wrong here
Encryption key management is typically handled between the malware agent and the C2 server through a secure handshake. The redirector simply passes the encrypted traffic through, unaware of the content or the keys. It does not perform cryptographic functions, as this would require it to decrypt the communication.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.