Courseiva

GPEN · topic practice

Command and Control practice questions

This domain covers establishing and maintaining covert channels between compromised hosts and attacker infrastructure, including beacon configuration, jitter, redirectors, and fallback channels. GPEN tests it through scenario questions on C2 frameworks like Metasploit and Cobalt Strike, asking you to configure listeners, interpret beacon parameters, choose resilient persistence methods, and identify which log sources reveal DNS or HTTP-based command and control.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Command and Control

What the exam tests

What to know about Command and Control

You must configure a working C2 listener, explain how jitter and beacon interval shape traffic, and choose resilient persistence methods. The single most important thing: know that DNS query and proxy logs are the highest-value detection sources, and that jitter exists to defeat timing-based beacon analysis.

Configuring Metasploit handlers and Cobalt Strike listeners with correct payload, port, and profile settings

Interpreting beacon interval, jitter, and sleep parameters and their effect on traffic patterns

Using redirectors, domain fronting, and fallback channels to survive infrastructure takedowns

Detecting C2 via DNS query logs, proxy logs, and NetFlow or Zeek connection records

Watch out for

Common Command and Control exam traps

  • ▸Confusing beacon interval with jitter: interval sets base sleep time, jitter randomizes it as a percentage to avoid predictable timing
  • ▸Assuming a single C2 server is resilient; takedown resistance requires redirectors, fallback channels, or domain rotation
  • ▸Overlooking DNS as a C2 channel because payloads are small; DNS query logs are the primary detection source for DNS tunneling

Practice set

Command and Control questions

20 questions · select your answer, then reveal the explanation

Which THREE techniques are commonly used by attackers to hide C2 traffic within legitimate network protocols?

Question 2mediummultiple choice
Read the full DNS explanation →

During an authorized penetration test, you successfully establish an interactive command and control shell via DNS tunneling. However, you notice that large data exfiltration queries are frequently failing or timing out due to upstream DNS server payload restrictions and strict rate limiting. Which action should you take to optimize reliability while maintaining covert persistence?

You are conducting a penetration test and have established a C2 channel using the Metasploit Framework's Meterpreter payload. You need to maintain persistence on the compromised Windows host while ensuring that the C2 communication survives reboots and user logoffs. Which two techniques can you use with Meterpreter to achieve this? (Choose two.)

During an authorized penetration test, you have established a Meterpreter session to a Windows 10 target over TCP port 443. The client's egress firewall begins inspecting TLS certificates and blocking self-signed certificates. Your session dies. You need a new payload that can survive this inspection while still using port 443. Which Metasploit payload is best suited?

Question 5hardmultiple choice
Read the full DNS explanation →

During a penetration test, you have compromised a host in a restricted network that only allows outbound DNS traffic. You need to establish a C2 channel. Which of the following techniques would be most effective for maintaining a reliable, low-bandwidth C2 channel over DNS?

During a penetration test, you have established a C2 session with a target host using a Meterpreter reverse HTTPS payload. You want to maintain access even if the user logs off or the system reboots. Which of the following methods is the MOST reliable for achieving persistence on a Windows host?

Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?

Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?

Exhibit

C2-Policy: { 'method': 'HTTPS', 'beacon_interval': '60s', 'jitter': '20%', 'encoding': 'base64', 'user_agent': 'Mozilla/5.0 (Windows NT 10.0)' }

Which term best describes the stage of a cyberattack where a compromised host signals a remote server to request instructions or transmit stolen data?

When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?

Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?

Exhibit

Error Log: [2023-10-12 14:02:11] SSL_connect failed: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca

Which of the following is a classic characteristic of 'beaconing' behavior observed in C2 traffic?

What is the primary risk of using 'Domain Fronting' in a C2 architecture during a penetration test?

Why do many C2 frameworks include a 'sleep' command that can be configured by the operator?

Question 15mediummultiple choice
Read the full DNS explanation →

When evaluating the security of an organization's C2 detection capabilities, which log source is the most valuable for detecting DNS-based C2?

An attacker uses a 'redirector' in their C2 infrastructure. What is the primary purpose of this architectural component?

Which of the following is the most effective way to detect C2 beacons that use jitter and randomized timing?

Question 18mediummultiple choice
Read the full DNS explanation →

During an internal penetration test, you have compromised a Windows workstation and need to establish a covert channel that will survive network address translation and filtering. You decide to use the Domain Name System (DNS) TXT record for command and control. Which tool should you use to create a DNS tunnel that encapsulates IP traffic over DNS queries and responses?

During an authorized penetration test, you have established a C2 session using a popular framework. Your goal is to maintain persistent access to a compromised Windows host even after the user logs off or the system reboots. You decide to use a service-based persistence mechanism. Which of the following commands, when executed on the compromised host, would create a new Windows service that runs your payload at startup?

You are performing an authorized penetration test and have established a C2 channel using HTTPS. To evade network detection, you configure your C2 beacon to use domain fronting. Which of the following best describes how domain fronting masks the true destination of your C2 traffic?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Command and Control sessions

Start a Command and Control only practice session

Every question in these sessions is drawn from the Command and Control domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Command and Control?
You must configure a working C2 listener, explain how jitter and beacon interval shape traffic, and choose resilient persistence methods. The single most important thing: know that DNS query and proxy logs are the highest-value detection sources, and that jitter exists to defeat timing-based beacon analysis.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Command and Control questions in a focused session?
Yes — the session launcher on this page draws every question from the Command and Control domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.