GPEN Command and Control Practice Question
When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?
⚠ Common exam trap
Candidates often overthink technical details like cipher suites or TLS versions. They miss the most obvious red flag: the lack of a trusted, verifiable certificate chain for a production-facing endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The certificate uses a self-signed or invalid chain.
Malicious C2 infrastructure often uses self-signed certificates or certificates issued by untrusted/free Certificate Authorities to encrypt traffic. In a professional environment, legitimate services typically use well-known, trusted CAs. When a penetration tester sees an endpoint using a certificate with a random common name, short expiration period, or invalid chain, it serves as a strong indicator that the connection is intended for unauthorized command and control purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The certificate uses a 2048-bit RSA key.
Why it's wrong here
A 2048-bit RSA key is a standard, secure cryptographic strength used by both legitimate businesses and sophisticated attackers. The key length itself does not indicate malice, as modern malware strives to appear legitimate by using standard, strong encryption to prevent man-in-the-middle inspection.
- ✗
The certificate is signed by a reputable public CA.
Why it's wrong here
Using a reputable public CA is a common technique for advanced adversaries to bypass SSL inspection policies. Because the certificate is trusted by the operating system, it does not trigger browser or OS warnings, making it a highly effective method for masquerading as legitimate traffic.
- ✓
The certificate uses a self-signed or invalid chain.
Why this is correct
Self-signed certificates are common in rapid-deployment C2 infrastructure because they are easy to generate and cost nothing. While they trigger warnings in a browser, malware can be configured to ignore these warnings, making them a telltale sign of non-standard, likely malicious, backend communication infrastructure.
- ✗
The certificate includes a valid Subject Alternative Name.
Why it's wrong here
A valid Subject Alternative Name field is a requirement for modern browser trust. Attackers wanting to blend in will often ensure their certificates are perfectly formatted. The presence of these fields is a sign of good configuration, not necessarily an indication of legitimate versus malicious traffic.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.