Courseiva

CCNA Command And Control Questions

24 questions · Command And Control topic · All types, answers revealed

1
MCQmedium

When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?

A.The certificate uses a 2048-bit RSA key.
B.The certificate is signed by a reputable public CA.
C.The certificate uses a self-signed or invalid chain.
D.The certificate includes a valid Subject Alternative Name.
AnswerC

Self-signed certificates are common in rapid-deployment C2 infrastructure because they are easy to generate and cost nothing. While they trigger warnings in a browser, malware can be configured to ignore these warnings, making them a telltale sign of non-standard, likely malicious, backend communication infrastructure.

Why this answer

Malicious C2 infrastructure often uses self-signed certificates or certificates issued by untrusted/free Certificate Authorities to encrypt traffic. In a professional environment, legitimate services typically use well-known, trusted CAs. When a penetration tester sees an endpoint using a certificate with a random common name, short expiration period, or invalid chain, it serves as a strong indicator that the connection is intended for unauthorized command and control purposes.

Exam trap

Candidates often overthink technical details like cipher suites or TLS versions. They miss the most obvious red flag: the lack of a trusted, verifiable certificate chain for a production-facing endpoint.

2
MCQmedium

Which of the following is a classic characteristic of 'beaconing' behavior observed in C2 traffic?

A.High-volume data exfiltration during business hours.
B.Consistent, periodic intervals between connections.
C.Randomized connections to various global IP addresses.
D.Traffic that exclusively utilizes UDP transport.
AnswerB

Beaconing relies on periodic check-ins to ensure the malware maintains its connection to the C2 server. This regularity, even if jitter is present, creates a distinct statistical signature in network traffic logs, allowing security analysts to identify compromised hosts that are systematically calling out to an external C2 node.

Why this answer

Beaconing is characterized by the repeated, predictable nature of the connection attempts from a compromised host to an external server. By analyzing network traffic, one can identify these 'heartbeats' that occur at fixed intervals. This pattern is often the first red flag that a system has been compromised, as legitimate user activity is typically irregular and bursty compared to the methodical, automated nature of a C2 beacon.

Exam trap

Candidates often confuse 'beaconing' with 'data exfiltration' or 'bursty traffic'. They fail to recognize that the defining characteristic of beaconing is the predictable, rhythmic timing of the connection attempts.

3
MCQmedium

During an authorized penetration test, you compromise a Windows host in a restricted network segment that only permits outbound DNS (UDP 53) to an internal resolver. You need to establish a command-and-control channel that can survive reboots and provide interactive shell access while blending with normal DNS traffic. Which of the following is the MOST appropriate technique to achieve this?

A.Use a DNS TXT record to store commands, and have the compromised host poll a public DNS server directly on UDP 53, bypassing the internal resolver.
B.Use a reverse TCP Meterpreter payload over port 443 with TLS, and rely on the firewall's deep packet inspection to allow it as HTTPS.
C.Use an ICMP tunnel such as ptunnel to encapsulate shell traffic in echo requests, and configure a registry run key for persistence.
D.Use a DNS tunneling tool such as dnscat2, configure it with a domain you control, and set up a scheduled task to restart the client on boot.
AnswerD

DNS tunneling encapsulates arbitrary data within DNS queries and responses, allowing interactive shell access over UDP 53. Since the network only allows DNS to an internal resolver, dnscat2 can still reach its external server if the resolver performs recursive lookups. Persistence via scheduled task ensures the channel re-establishes after reboot. This combination directly addresses the constraints.

Why this answer

The scenario requires a C2 channel that works over DNS only, supports interactive shell, and survives reboots. DNS tunneling via dnscat2 meets these requirements because it encapsulates data in DNS queries and responses, which are allowed. Persistence via scheduled task ensures the client restarts after a reboot.

The other options either violate the allowed protocol (TCP/443, ICMP) or attempt to bypass the internal resolver, which is not permitted.

Exam trap

The trap here is assuming that any outbound connection can be tunneled over DNS, but the key constraint is that only DNS to an internal resolver is allowed, so direct public DNS or other protocols are blocked.

4
MCQhard

What is the primary risk of using 'Domain Fronting' in a C2 architecture during a penetration test?

A.It will trigger an immediate alert on all EDR agents.
B.It can cause accidental disruption to legitimate services.
C.It is easily detectable by standard firewall port filtering.
D.It forces the malware to use a non-standard protocol.
AnswerB

Because domain fronting shares infrastructure with legitimate traffic, blocking the C2 traffic often requires blocking the entire CDN host header or IP range. Doing this in a production environment during a penetration test could inadvertently block legitimate business applications, leading to significant operational downtime and client dissatisfaction.

Why this answer

Domain fronting relies on the trust placed in large Content Delivery Networks (CDNs). If a penetration tester uses a high-traffic, reputable CDN for C2, the organization's defense team may be unable to block the C2 traffic without also blocking legitimate business services that share the same CDN infrastructure. This creates a significant conflict between security needs and operational availability, which must be carefully managed during the engagement.

Exam trap

Examinees often think domain fronting risks involve immediate decryption by firewalls or automatic host crashing, ignoring the operational dilemma it causes for defenders.

5
MCQmedium

Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?

A.The C2 server is unreachable due to a network outage.
B.The client system does not trust the C2 server's certificate.
C.The C2 server is performing a man-in-the-middle attack.
D.The C2 server has exhausted its connection limit.
AnswerB

This specific TLS alert signifies that the client received a certificate it could not verify against its local root store. This is a common indicator that the C2 infrastructure is using a self-signed certificate, which the client is configured to reject due to strict security settings.

Why this answer

The 'tlsv1 alert unknown ca' error indicates that the client rejected the server's certificate because it was not signed by a trusted root CA. In the context of C2, this often happens when an automated beacon tries to connect to an infrastructure node using a self-signed certificate, and the host's security policy or a proxy is performing SSL inspection and fails the trust validation process.

Exam trap

Candidates often assume this error means the server is down or the network is blocked. They miss that the error is specifically a certificate validation failure by the client system.

6
MCQmedium

When evaluating the security of an organization's C2 detection capabilities, which log source is the most valuable for detecting DNS-based C2?

A.Endpoint system event logs.
B.Centralized DNS query logs.
C.Firewall traffic logs (Layer 4).
D.Antivirus detection logs.
AnswerB

DNS logs contain the full query history, including the requested domain names and the record types used. This is the most effective data source for detecting DNS tunneling, as it allows analysts to perform statistical analysis and identify patterns indicative of covert channels and malicious name resolution.

Why this answer

DNS query logs are the primary data source for identifying DNS-based C2. By analyzing these logs, security teams can identify anomalies such as high volumes of queries to a specific domain, unusual record types like TXT or NULL records, or domains with extremely high entropy. Without centralized DNS logging, detecting this specific type of C2 becomes nearly impossible, as the traffic occurs at the infrastructure level rather than the end-host level.

Exam trap

Students mistakenly choose endpoint antivirus logs or firewall packet captures, forgetting that DNS traffic happens entirely at the infrastructure level via name resolution.

7
MCQmedium

During an internal penetration test, you have compromised a Windows workstation and need to establish a covert channel that will survive network address translation and filtering. You decide to use the Domain Name System (DNS) TXT record for command and control. Which tool should you use to create a DNS tunnel that encapsulates IP traffic over DNS queries and responses?

A.iodine
B.dnscat2
C.dns2tcp
D.iodine-client
AnswerA

iodine is a DNS tunneling tool that encodes IPv4 data within DNS queries and responses, typically using NULL or TXT record types. It creates a virtual network interface (dns0) and can tunnel IP traffic through a DNS server you control. It is specifically designed for this purpose and is widely used in penetration testing to bypass captive portals and egress filtering.

Why this answer

The correct tool for encapsulating IP traffic over DNS is iodine. It creates a virtual network interface and tunnels IPv4 packets inside DNS queries and responses, effectively providing a VPN over DNS. This allows the attacker to bypass network restrictions that only allow DNS traffic.

Other tools like dnscat2 and dns2tcp provide C2 channels but do not encapsulate IP traffic.

Exam trap

The trap here is confusing DNS tunneling tools that provide command-and-control channels with those that encapsulate IP traffic, such as iodine.

8
MCQeasy

Which term best describes the stage of a cyberattack where a compromised host signals a remote server to request instructions or transmit stolen data?

A.Privilege escalation
B.Command and control
C.Reconnaissance
D.Log clearing
AnswerB

Command and control is the industry-standard term for the maintenance of a communication channel between a compromised asset and an external adversary. This phase allows the attacker to maintain presence, send operational commands, and monitor the progress of their mission within the target environment.

Why this answer

The command and control (C2) phase represents the ongoing communication channel between the attacker's infrastructure and the compromised system. It is the tactical link that allows the adversary to remotely manage the infection, deploy additional tools, and exfiltrate information. Recognizing C2 traffic is fundamental to incident response because it is the primary vector for controlling the adversary's actions within the network environment.

Exam trap

Examinees often confuse the command and control phase with initial access, lateral movement, or data exfiltration, missing the definition of ongoing management communication.

9
MCQeasy

A penetration tester has compromised a host in a restricted network that only allows outbound DNS queries to a specific internal resolver. The tester needs to establish a command and control channel that can traverse this restriction. Which C2 technique is most appropriate?

A.SMTP beaconing
B.ICMP tunneling
C.HTTPS beaconing
D.DNS tunneling
AnswerD

DNS tunneling encapsulates C2 data within DNS queries and responses, which are allowed through the restricted network. Since only DNS traffic to the internal resolver is permitted, this technique can bypass the egress filtering. Tools like dnscat2 or iodine can establish a covert channel over DNS. This directly addresses the scenario's constraint and is a common method for C2 in heavily restricted environments.

Why this answer

DNS tunneling is the only technique that can operate within a network that only allows DNS queries to an internal resolver. It encapsulates C2 traffic within DNS packets, which are forwarded by the resolver to external authoritative servers. This makes it ideal for bypassing strict egress filtering.

Other techniques require protocols or ports that are not permitted in this scenario.

Exam trap

The trap here is assuming that common web-based C2 like HTTPS will work, but the network only permits DNS traffic to a specific resolver.

10
Multi-Selectmedium

You are configuring a C2 listener to use a malleable profile to blend in with legitimate traffic. Which two of the following are key benefits of using a malleable C2 profile in a penetration test? (Choose two.)

Select 2 answers
A.It enables the C2 server to automatically generate new domain names for each beacon, avoiding domain blacklisting.
B.It provides a mechanism to define how the C2 server responds to specific requests, including error pages and other decoy content.
C.It encrypts the C2 traffic using a unique, randomly generated key for each session, ensuring perfect forward secrecy.
D.It allows the C2 traffic to be routed through multiple redirectors without additional configuration.
E.It allows you to customize the HTTP headers, URIs, and other request parameters to mimic a specific application or service.
AnswersB, E

Malleable C2 profiles allow operators to specify server responses, such as HTTP status codes, headers, and body content. This can include decoy pages or error messages that make the C2 server appear as a legitimate web server. By controlling responses, operators can further blend in and mislead defenders. This is a key benefit for maintaining stealth during a penetration test.

Why this answer

Malleable C2 profiles are used to customize the network traffic generated by a C2 framework to evade detection. They allow operators to define request and response structures, including headers, URIs, and body content, so that the traffic mimics legitimate services. This customization helps in blending with normal network activity and avoiding signature-based detection, making it a valuable tool during penetration tests.

Exam trap

The trap here is assuming malleable profiles provide encryption or domain generation, which are separate techniques, rather than focusing on traffic shaping and customization.

11
MCQmedium

Which of the following is the most effective way to detect C2 beacons that use jitter and randomized timing?

A.Blocking all traffic to unknown IP addresses.
B.Applying statistical analysis to traffic patterns.
C.Scanning for specific byte signatures in the payloads.
D.Monitoring for high-bandwidth bursts in the network.
AnswerB

Statistical analysis looks for patterns that emerge over time, such as the mean interval between connections. Even with jitter, the underlying periodicity remains detectable. This method allows security teams to identify the 'pulse' of a C2 channel even when it is intentionally obfuscated by random timing variations.

Why this answer

Since jitter and randomized timing break the simple periodic heartbeat, security teams must use statistical analysis to identify the traffic. By calculating the frequency distribution of connections over a long time window, analysts can identify the underlying regularity that persists despite the jitter. This behavioral approach is significantly more effective than static threshold-based alerts, which are easily defeated by the randomness built into modern C2 communication protocols.

Exam trap

Candidates often assume that because jitter makes beacons appear non-periodic, simple detection methods like frequency analysis are useless, failing to realize that statistical aggregation over long periods still reveals underlying regularity.

12
Multi-Selectmedium

You are designing a resilient command-and-control (C2) infrastructure for an authorized penetration test. The client's network has strict egress filtering and monitors for anomalous traffic. You need to ensure that your C2 channel can survive the takedown of a single server and adapt to changing network conditions. Which two of the following techniques should you implement? (Choose two.)

Select 2 answers
A.Implement a fallback channel that uses a different protocol (e.g., DNS) if the primary channel is blocked.
B.Enable jitter and sleep intervals to randomize beacon timing and avoid pattern-based detection.
C.Use multiple redirectors with domain fronting to distribute traffic and hide the true C2 server.
D.Configure the C2 client to use a single hardcoded IP address for the C2 server to simplify reconnection.
E.Use a single domain name with a long TTL to minimize DNS lookups and reduce the chance of detection.
AnswersA, C

A fallback channel provides an alternative communication path if the primary protocol is blocked or degraded. For example, if HTTPS is blocked, the client can switch to DNS tunneling. This adaptability ensures continued command and control even when network conditions change or defenses are updated. It is a key component of resilient C2 design.

Why this answer

Resilient C2 infrastructure requires redundancy and adaptability. Multiple redirectors with domain fronting provide redundancy and hide the true server, making takedown more difficult. A fallback channel using a different protocol ensures communication continues if the primary channel is blocked.

These two techniques directly address survivability and adaptability. The other options either introduce single points of failure or focus on stealth rather than resilience.

Exam trap

The trap here is confusing stealth techniques like jitter with resilience techniques; jitter helps avoid detection but does not help if the C2 server is taken offline.

13
MCQhard

You are conducting a penetration test against a target that employs a next-generation firewall (NGFW) with SSL inspection. Your C2 channel uses a custom protocol over TCP port 8443 with a self-signed certificate. The NGFW is blocking your traffic. You need to modify your C2 configuration to evade detection while maintaining command and control. Which of the following changes is MOST likely to succeed?

A.Switch to using a legitimate code-signing certificate issued by a trusted CA and mimic the TLS fingerprint of a common web browser.
B.Configure the C2 client to use a random port above 1024 and implement jitter in the beacon interval to avoid pattern detection.
C.Use a domain fronting technique with a popular CDN to hide the true destination, and keep the self-signed certificate.
D.Encapsulate the C2 traffic within DNS queries to a domain you control, using a high volume of queries to avoid detection.
AnswerA

SSL inspection decrypts traffic and can block self-signed certificates or anomalous TLS fingerprints. By using a trusted CA certificate and mimicking a browser's TLS fingerprint (e.g., via JA3), the traffic appears legitimate and may bypass inspection. This approach blends with normal HTTPS traffic, making it harder for the NGFW to distinguish malicious C2 from benign web browsing.

Why this answer

The NGFW's SSL inspection is blocking the C2 because it can decrypt the traffic and detect the self-signed certificate or suspicious TLS characteristics. To evade this, the C2 must present a trusted certificate and mimic a legitimate browser's TLS handshake. This makes the traffic indistinguishable from normal HTTPS.

The other options either do not address SSL inspection (jitter, port change) or retain the self-signed certificate (domain fronting), which would still be flagged.

Exam trap

The trap here is focusing on network-level obfuscation like jitter or port changes while ignoring that SSL inspection operates at the application layer and will still detect a self-signed certificate.

14
MCQhard

You are using a C2 framework that supports malleable C2 profiles. Your current profile uses a default HTTP GET beacon with a fixed User-Agent and a URI of /submit.php. The target's network monitoring has flagged this traffic as suspicious. You need to modify the profile to better blend with legitimate traffic. Which of the following changes is the MOST effective for evading network-based detection?

A.Increase the beacon interval to several hours and add large amounts of jitter to make the traffic less frequent and more random.
B.Enable HTTPS with a valid certificate and use a domain that is categorized as 'business' by the firewall's URL filtering.
C.Mimic a legitimate application's traffic pattern by using its specific User-Agent, URI structure, and request headers, and set the beacon interval to match its typical polling frequency.
D.Change the User-Agent to match a common browser and set the URI to a random string for each beacon.
AnswerC

The most effective way to blend in is to fully emulate a legitimate application's communication patterns. This includes not only the User-Agent and URI but also headers, parameter names, and timing. If the C2 traffic matches the application's normal behavior, network monitoring will have difficulty distinguishing it from legitimate traffic. This approach addresses multiple detection vectors simultaneously.

Why this answer

To evade network-based detection, the C2 traffic must closely resemble legitimate traffic. Simply changing the User-Agent or URI is insufficient because the overall pattern may still be anomalous. The most effective approach is to fully emulate a legitimate application, including its headers, URI structure, and timing.

This makes the C2 traffic indistinguishable from the application's normal traffic, bypassing both signature and anomaly-based detection. The other options only partially address the problem.

Exam trap

The trap here is thinking that changing the User-Agent or URI is enough, but modern detection systems baseline application behavior and will flag random or inconsistent patterns.

15
MCQhard

During a penetration test, you have established a C2 channel using a domain fronting technique with a CDN. The target organization's proxy logs show connections to a high-reputation domain, but the actual C2 traffic is destined for your backend server. Which component is essential for this setup to function?

A.An HTTP redirect from the high-reputation domain to your backend server.
B.A DNS TXT record pointing to your backend server.
C.A CDN that supports domain fronting and allows you to configure the Host header separately from the SNI.
D.A valid SSL certificate for the high-reputation domain on your backend server.
AnswerC

Domain fronting relies on the CDN accepting a Host header that differs from the SNI. The CDN routes based on the Host header to your backend, while the SNI shows a high-reputation domain. This requires CDN support for domain fronting, which some providers have disabled. Without this, the technique fails. Thus, this component is essential.

Why this answer

Domain fronting requires a CDN that permits the Host header to differ from the SNI. The CDN uses the Host header to route to the correct backend, while the SNI shows a trusted domain. This makes the traffic appear to go to a high-reputation domain.

Without CDN support, the technique cannot work. Other options are either handled by the CDN or irrelevant to the mechanism.

Exam trap

The trap here is assuming that the backend server needs a certificate for the fronted domain, but the CDN terminates TLS and presents its own certificate.

16
MCQmedium

Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?

A.To reduce the CPU overhead on the infected host.
B.To synchronize beaconing across multiple infected hosts.
C.To prevent detection via traffic pattern analysis.
D.To increase the throughput of the C2 channel.
AnswerC

Traffic pattern analysis identifies beacons by looking for regular, periodic intervals. By adding 20% jitter to a 60-second interval, the check-in occurs between 48 and 72 seconds. This variation breaks the statistical regularity, making it much harder to distinguish from legitimate user-initiated web browsing activity.

Why this answer

The jitter parameter introduces a random percentage of variation into the beacon interval, preventing the C2 traffic from appearing as a perfectly rhythmic heartbeat. Static intervals are highly detectable through statistical analysis, as they create distinct patterns in network traffic logs. Introducing jitter makes the C2 communication appear more organic and unpredictable, complicating efforts by defenders to identify the malicious connection using simple frequency-based anomaly detection algorithms.

Exam trap

Examinees often guess that jitter is used to speed up data exfiltration or evade simple port blocking, confusing timing randomization with protocol obfuscation methods.

17
MCQmedium

Why do many C2 frameworks include a 'sleep' command that can be configured by the operator?

A.To allow the malware to clear its memory footprint.
B.To minimize the visibility of the C2 beacon.
C.To bypass the need for a persistent connection.
D.To prevent the target from shutting down the system.
AnswerB

High-frequency beaconing is a very loud indicator of compromise. By increasing the sleep interval, an operator can make the beaconing activity appear much less frequent, significantly reducing the probability of detection by behavioral analysis tools that look for rapid, repeated connections to an external command server.

Why this answer

The 'sleep' command allows an operator to control the frequency of beaconing manually. This is useful for balancing the need for responsiveness with the need for stealth. By increasing the sleep time, the operator makes the beacon less frequent, which reduces the chance of detection by network anomaly systems.

This flexibility is a core feature of modern C2 suites, enabling operators to manage the trade-off between active engagement and operational security.

Exam trap

Candidates frequently assume the sleep command is designed to reduce CPU utilization on the compromised host, rather than lowering network traffic visibility.

18
MCQmedium

You are setting up a C2 infrastructure for a penetration test. To protect the backend C2 server from direct exposure, you deploy a redirector. Which of the following best describes the primary function of a redirector in this context?

A.It generates random domain names for the C2 server to evade domain blacklisting.
B.It acts as a proxy that forwards only malicious traffic to the C2 server while blocking or misdirecting other traffic.
C.It load-balances incoming connections across multiple C2 servers to ensure high availability.
D.It encrypts all traffic between the compromised host and the C2 server, ensuring confidentiality.
AnswerB

A redirector is designed to filter incoming traffic, allowing only connections that match specific criteria (e.g., a secret header or specific URI) to reach the backend C2 server. Other traffic, such as from security researchers or scanners, is blocked or redirected to a benign site. This protects the C2 server's identity and location, making it harder for defenders to identify and block the actual C2 infrastructure.

Why this answer

A redirector's primary function is to act as a proxy that filters incoming traffic, forwarding only legitimate C2 traffic to the backend server while blocking or misdirecting other connections. This protects the C2 server's location and makes it more difficult for defenders to identify and block the actual C2 infrastructure. Encryption, load balancing, and domain generation are separate concerns handled by other components or techniques.

Exam trap

The trap here is confusing the redirector's filtering role with encryption or domain generation, which are separate C2 components.

19
MCQhard

You are performing an authorized penetration test and have established a C2 channel using HTTPS. To evade network detection, you configure your C2 beacon to use domain fronting. Which of the following best describes how domain fronting masks the true destination of your C2 traffic?

A.The TLS SNI field contains the domain of a legitimate high-reputation service, while the HTTP Host header contains the actual C2 domain.
B.The C2 traffic is routed through multiple compromised hosts in a peer-to-peer network, making it difficult to trace back to the origin.
C.The TLS SNI field contains the actual C2 domain, while the HTTP Host header contains the domain of a legitimate service.
D.The C2 traffic is encapsulated within DNS queries to a legitimate domain, and the responses contain the C2 instructions.
AnswerA

Domain fronting exploits the difference between the TLS SNI (which is visible in the clear during the TLS handshake) and the HTTP Host header (which is encrypted). By setting the SNI to a legitimate domain hosted on a CDN and the Host header to the C2 domain also hosted on the same CDN, network observers see only the SNI and assume the traffic is to the legitimate domain. The CDN routes the request based on the Host header to the actual C2 server.

Why this answer

Domain fronting works by manipulating the TLS SNI and HTTP Host header. The SNI, visible during the TLS handshake, points to a legitimate domain hosted on a CDN, while the encrypted Host header points to the actual C2 domain also hosted on the same CDN. This makes the traffic appear to be destined for the legitimate domain to network observers, effectively hiding the C2 communication.

Exam trap

The trap here is reversing the SNI and Host header roles, or confusing domain fronting with other evasion techniques like DNS tunneling or P2P.

20
MCQmedium

During an authorized penetration test, you have established a C2 session using a popular framework. Your goal is to maintain persistent access to a compromised Windows host even after the user logs off or the system reboots. You decide to use a service-based persistence mechanism. Which of the following commands, when executed on the compromised host, would create a new Windows service that runs your payload at startup?

A.wmic service create name='Updater' path='C:\Windows\Temp\payload.exe' startmode='Auto'
B.schtasks /create /tn "Updater" /tr "C:\Windows\Temp\payload.exe" /sc onlogon
C.sc create Updater binPath= "C:\Windows\Temp\payload.exe" start= auto
D.reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Windows\Temp\payload.exe"
AnswerC

This command uses the Windows Service Control Manager to create a new service named 'Updater' that runs the specified payload executable automatically at system startup. The syntax with spaces after equals signs is required for sc.exe. This achieves persistence because the service will start each time Windows boots, maintaining the C2 channel without relying on user logon.

Why this answer

Creating a Windows service with sc.exe is a reliable method for achieving persistence because services can be configured to start automatically at boot, independent of user logon. The command must use the correct syntax with spaces after 'binPath=' and 'start='. Other options either rely on user logon or use invalid syntax, failing to meet the requirement of persistence across reboots without user interaction.

Exam trap

The trap here is confusing user-logon persistence (Run keys, onlogon tasks) with system-boot persistence (services), which does not require a user to log in.

21
MCQhard

An attacker uses a 'redirector' in their C2 infrastructure. What is the primary purpose of this architectural component?

A.To increase the bandwidth of the C2 connection.
B.To provide a layer of obfuscation for the C2 server.
C.To translate commands into local system calls.
D.To manage the encryption keys for the C2 channel.
AnswerB

Redirectors hide the true IP address of the C2 server by serving as a proxy. If a redirector is identified and blocked, the attacker can quickly pivot to a new redirector while the primary C2 server remains safely tucked away, ensuring the core infrastructure stays operational.

Why this answer

Redirectors act as a layer of separation between the compromised host and the actual C2 server. They proxy the incoming beacon traffic to the real server, masking the location of the true command infrastructure. This protects the C2 server from being directly identified and blacklisted, as the traffic appears to originate from the redirector node.

This is a critical component for maintaining a resilient and stealthy operational environment.

Exam trap

Candidates often assume a redirector is meant to increase connection speed or provide redundancy. They miss its primary tactical purpose: hiding the true location of the C2 server.

22
MCQhard

Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?

A.Implementing Domain Generation Algorithms (DGA).
B.Hardcoding the IP address of the C2 server.
C.Utilizing cloud providers for domain fronting.
D.Using unencrypted HTTP for all C2 traffic.
E.Requiring manual operator interaction for beaconing.
AnswerA, C

DGA allows malware to generate a vast number of pseudo-random domain names daily. The attacker only needs to register a small subset of these to maintain connectivity. This provides massive redundancy, as defenders cannot easily block all potential future domains before they are registered by the adversary.

Why this answer

Resilient C2 infrastructure often relies on decentralized or dynamic components to ensure that the connection remains viable even if individual nodes are identified and blocked. By utilizing domain generation algorithms and cloud-based relay services, attackers create a moving target that is difficult for incident responders to fully dismantle in a timely manner. Mastery of these techniques is essential for assessing the robust nature of an organization's defense-in-depth posture.

Exam trap

Test-takers frequently confuse persistence mechanisms meant to survive reboots (like registry run keys) with techniques designed specifically for resilient C2 infrastructure takedown defense.

23
MCQmedium

You are configuring a Cobalt Strike beacon for a penetration test. The client's security team monitors for periodic beaconing patterns. You want to reduce the chance of detection by network behavior analysis. Which beacon setting should you adjust?

A.Change the user agent to match a common browser.
B.Use a self-signed certificate for the HTTPS listener.
C.Increase the sleep time and add jitter.
D.Enable the TCP beacon instead of HTTPS.
AnswerC

Increasing sleep time reduces the frequency of beacon check-ins, and adding jitter introduces randomness to the intervals. This makes the traffic less periodic and harder to detect via timing analysis. Network behavior analytics often flag regular intervals, so jitter helps break that pattern. This directly addresses the concern about periodic beaconing detection.

Why this answer

Adjusting sleep time and jitter directly modifies the beacon's communication schedule, making it less predictable. Longer sleep intervals reduce traffic volume, and jitter adds randomness, breaking the periodic pattern that network behavior analysis seeks. Other options affect different layers (application headers, transport, or TLS) but do not address the timing-based detection described.

Exam trap

The trap here is thinking that changing the user agent or certificate will hide the beacon, but the detection is based on timing patterns, not content.

24
Multi-Selecthard

You are using Cobalt Strike in an authorized penetration test. The target network uses a next-generation firewall that performs SSL inspection and blocks self-signed certificates. You need to configure your HTTPS beacon to blend in with legitimate traffic and avoid detection. (Choose two.)

Select 2 answers
A.Enable the TCP beacon instead of the HTTPS beacon.
B.Use a self-signed certificate but set the beacon's user agent to match a common browser.
C.Set the beacon's sleep time to 60 seconds with 30% jitter.
D.Configure the beacon to use a malleable C2 profile that mimics a known application like Microsoft Outlook Web Access.
E.Use a valid SSL certificate from a trusted certificate authority for the C2 listener.
AnswersD, E

A malleable C2 profile customizes the beacon's network traffic to resemble a legitimate application. By mimicking Outlook Web Access, the traffic's HTTP headers, URIs, and other characteristics match normal OWA usage. This helps evade deep packet inspection and application-based blocking, complementing the valid certificate. It makes the beacon traffic blend in with expected enterprise traffic, reducing the chance of detection.

Why this answer

To evade SSL inspection and blend in, using a valid certificate from a trusted CA ensures the TLS handshake is accepted, and a malleable C2 profile mimicking a known application like OWA makes the traffic appear legitimate at the application layer. Together, they address both certificate trust and traffic pattern detection. Other options do not resolve the certificate blocking or are less effective for blending.

Exam trap

The trap here is focusing solely on traffic shaping (sleep/jitter) or user agent strings while overlooking the need for a trusted certificate to pass SSL inspection.

Ready to test yourself?

Try a timed practice session using only Command And Control questions.