Courseiva
Command and Control →easyMultiple Choice

GPEN Command and Control Practice Question

Which term best describes the stage of a cyberattack where a compromised host signals a remote server to request instructions or transmit stolen data?

⚠ Common exam trap

Examinees often confuse the command and control phase with initial access, lateral movement, or data exfiltration, missing the definition of ongoing management communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command and control

The command and control (C2) phase represents the ongoing communication channel between the attacker's infrastructure and the compromised system. It is the tactical link that allows the adversary to remotely manage the infection, deploy additional tools, and exfiltrate information. Recognizing C2 traffic is fundamental to incident response because it is the primary vector for controlling the adversary's actions within the network environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Privilege escalation

    Why it's wrong here

    Privilege escalation is the process of exploiting vulnerabilities to gain higher-level permissions on a local system. While the C2 channel might be used to send commands to perform this action, the phase itself refers specifically to the escalation of rights, not the communication link being established.

  • ✓

    Command and control

    Why this is correct

    Command and control is the industry-standard term for the maintenance of a communication channel between a compromised asset and an external adversary. This phase allows the attacker to maintain presence, send operational commands, and monitor the progress of their mission within the target environment.

  • ✗

    Reconnaissance

    Why it's wrong here

    Reconnaissance is the initial phase where an attacker gathers information about the target system or organization. It occurs before a foothold is established and typically involves passive scanning, open-source intelligence gathering, or probing of network services to identify potential vulnerabilities for later exploitation.

  • ✗

    Log clearing

    Why it's wrong here

    Log clearing is a post-exploitation activity intended to hide the attacker's tracks and prevent discovery. It involves removing evidence of unauthorized access, such as audit logs or temporary files, and is distinct from the ongoing, active communication channel defined by C2 infrastructure.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.