GPEN Command and Control Practice Question
During a penetration test, you have established a C2 channel using a domain fronting technique with a CDN. The target organization's proxy logs show connections to a high-reputation domain, but the actual C2 traffic is destined for your backend server. Which component is essential for this setup to function?
⚠ Common exam trap
The trap here is assuming that the backend server needs a certificate for the fronted domain, but the CDN terminates TLS and presents its own certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A CDN that supports domain fronting and allows you to configure the Host header separately from the SNI.
Domain fronting requires a CDN that permits the Host header to differ from the SNI. The CDN uses the Host header to route to the correct backend, while the SNI shows a trusted domain. This makes the traffic appear to go to a high-reputation domain. Without CDN support, the technique cannot work. Other options are either handled by the CDN or irrelevant to the mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An HTTP redirect from the high-reputation domain to your backend server.
Why it's wrong here
Domain fronting does not use HTTP redirects. The client sends the request to the CDN with a Host header for your backend, and the CDN forwards it internally. A redirect would expose the backend domain to the client and proxy logs, defeating the purpose. Therefore, this is not essential and would break the obfuscation.
- ✗
A DNS TXT record pointing to your backend server.
Why it's wrong here
Domain fronting does not use DNS TXT records for routing. The CDN routes traffic based on the Host header. DNS resolution points to the CDN's IP address, not your backend. TXT records are irrelevant to this technique. Thus, this component is not needed and would not facilitate domain fronting.
- ✓
A CDN that supports domain fronting and allows you to configure the Host header separately from the SNI.
Why this is correct
Domain fronting relies on the CDN accepting a Host header that differs from the SNI. The CDN routes based on the Host header to your backend, while the SNI shows a high-reputation domain. This requires CDN support for domain fronting, which some providers have disabled. Without this, the technique fails. Thus, this component is essential.
- ✗
A valid SSL certificate for the high-reputation domain on your backend server.
Why it's wrong here
In domain fronting, the TLS connection is terminated at the CDN, not your backend. The CDN presents its own certificate for the high-reputation domain. Your backend server does not need a certificate for that domain. Therefore, this is not essential; the CDN handles TLS. Requiring a certificate on the backend would be incorrect and impractical.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.