GPEN Command and Control Practice Question
Exhibit
C2-Policy: { 'method': 'HTTPS', 'beacon_interval': '60s', 'jitter': '20%', 'encoding': 'base64', 'user_agent': 'Mozilla/5.0 (Windows NT 10.0)' }Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?
⚠ Common exam trap
Examinees often guess that jitter is used to speed up data exfiltration or evade simple port blocking, confusing timing randomization with protocol obfuscation methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To prevent detection via traffic pattern analysis.
The jitter parameter introduces a random percentage of variation into the beacon interval, preventing the C2 traffic from appearing as a perfectly rhythmic heartbeat. Static intervals are highly detectable through statistical analysis, as they create distinct patterns in network traffic logs. Introducing jitter makes the C2 communication appear more organic and unpredictable, complicating efforts by defenders to identify the malicious connection using simple frequency-based anomaly detection algorithms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To reduce the CPU overhead on the infected host.
Why it's wrong here
Reducing CPU overhead is typically managed through efficient coding practices or long sleep intervals rather than randomizing the timing. While jitter affects when the code executes, its technical intent is to obfuscate traffic patterns, not to optimize performance or resource consumption on the target system.
- ✗
To synchronize beaconing across multiple infected hosts.
Why it's wrong here
Jitter is explicitly designed to desynchronize beaconing. If all hosts were synchronized to check in at the exact same moment, it would create a massive spike in traffic that is easily identified by network monitors. Synchronization is generally avoided by attackers to minimize the risk of detection.
- ✓
To prevent detection via traffic pattern analysis.
Why this is correct
Traffic pattern analysis identifies beacons by looking for regular, periodic intervals. By adding 20% jitter to a 60-second interval, the check-in occurs between 48 and 72 seconds. This variation breaks the statistical regularity, making it much harder to distinguish from legitimate user-initiated web browsing activity.
- ✗
To increase the throughput of the C2 channel.
Why it's wrong here
Jitter has no impact on throughput or the data transmission rate. Throughput is determined by the payload size, the number of check-ins, and the available bandwidth of the network connection. Jitter only affects the timing of the connection attempts, not the volume of data transferred during those attempts.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.