GPEN Command and Control Practice Question
What is the primary risk of using 'Domain Fronting' in a C2 architecture during a penetration test?
⚠ Common exam trap
Examinees often think domain fronting risks involve immediate decryption by firewalls or automatic host crashing, ignoring the operational dilemma it causes for defenders.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It can cause accidental disruption to legitimate services.
Domain fronting relies on the trust placed in large Content Delivery Networks (CDNs). If a penetration tester uses a high-traffic, reputable CDN for C2, the organization's defense team may be unable to block the C2 traffic without also blocking legitimate business services that share the same CDN infrastructure. This creates a significant conflict between security needs and operational availability, which must be carefully managed during the engagement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It will trigger an immediate alert on all EDR agents.
Why it's wrong here
Domain fronting happens at the network layer and is not directly visible to endpoint detection and response (EDR) agents unless they specifically monitor network traffic at the packet level. It is a network-based obfuscation technique that generally does not trigger host-based alerts simply by virtue of its existence.
- ✓
It can cause accidental disruption to legitimate services.
Why this is correct
Because domain fronting shares infrastructure with legitimate traffic, blocking the C2 traffic often requires blocking the entire CDN host header or IP range. Doing this in a production environment during a penetration test could inadvertently block legitimate business applications, leading to significant operational downtime and client dissatisfaction.
- ✗
It is easily detectable by standard firewall port filtering.
Why it's wrong here
Domain fronting operates over HTTPS (port 443), which is standard for web traffic. Blocking port 443 would break almost all web access for the organization. Therefore, standard port filtering is completely ineffective against this technique, as the traffic is indistinguishable from the organization's normal, authorized web browsing.
- ✗
It forces the malware to use a non-standard protocol.
Why it's wrong here
Domain fronting does not force the use of non-standard protocols. It is designed to work exclusively with standard HTTP/HTTPS traffic. The malware behaves like a normal web client, making requests that appear perfectly legitimate to the organization's network monitoring systems and security appliances.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.