GPEN Command and Control Practice Question
Why do many C2 frameworks include a 'sleep' command that can be configured by the operator?
⚠ Common exam trap
Candidates frequently assume the sleep command is designed to reduce CPU utilization on the compromised host, rather than lowering network traffic visibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To minimize the visibility of the C2 beacon.
The 'sleep' command allows an operator to control the frequency of beaconing manually. This is useful for balancing the need for responsiveness with the need for stealth. By increasing the sleep time, the operator makes the beacon less frequent, which reduces the chance of detection by network anomaly systems. This flexibility is a core feature of modern C2 suites, enabling operators to manage the trade-off between active engagement and operational security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To allow the malware to clear its memory footprint.
Why it's wrong here
Clearing a memory footprint requires specific obfuscation or self-injection techniques, not an idle sleep command. Sleeping keeps the process alive in memory. While the process is inactive while sleeping, it remains present in system RAM, where it can still be found by memory forensic tools.
- ✓
To minimize the visibility of the C2 beacon.
Why this is correct
High-frequency beaconing is a very loud indicator of compromise. By increasing the sleep interval, an operator can make the beaconing activity appear much less frequent, significantly reducing the probability of detection by behavioral analysis tools that look for rapid, repeated connections to an external command server.
- ✗
To bypass the need for a persistent connection.
Why it's wrong here
A beaconing architecture does not require a persistent connection; it is inherently a series of individual requests. The 'sleep' command merely dictates the interval between these individual requests. It does not replace the fundamental need for the malware to periodically connect to the server to check for instructions.
- ✗
To prevent the target from shutting down the system.
Why it's wrong here
The sleep command has no influence on the host system's power management or operational state. It is an internal timer within the malicious agent itself, designed only to control the timing of network communication, not the behavior of the host machine or its operating system services.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.