Courseiva
Command and Control →hardMultiple Choice

GPEN Command and Control Practice Question

You are conducting a penetration test against a target that employs a next-generation firewall (NGFW) with SSL inspection. Your C2 channel uses a custom protocol over TCP port 8443 with a self-signed certificate. The NGFW is blocking your traffic. You need to modify your C2 configuration to evade detection while maintaining command and control. Which of the following changes is MOST likely to succeed?

⚠ Common exam trap

The trap here is focusing on network-level obfuscation like jitter or port changes while ignoring that SSL inspection operates at the application layer and will still detect a self-signed certificate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Switch to using a legitimate code-signing certificate issued by a trusted CA and mimic the TLS fingerprint of a common web browser.

The NGFW's SSL inspection is blocking the C2 because it can decrypt the traffic and detect the self-signed certificate or suspicious TLS characteristics. To evade this, the C2 must present a trusted certificate and mimic a legitimate browser's TLS handshake. This makes the traffic indistinguishable from normal HTTPS. The other options either do not address SSL inspection (jitter, port change) or retain the self-signed certificate (domain fronting), which would still be flagged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Switch to using a legitimate code-signing certificate issued by a trusted CA and mimic the TLS fingerprint of a common web browser.

    Why this is correct

    SSL inspection decrypts traffic and can block self-signed certificates or anomalous TLS fingerprints. By using a trusted CA certificate and mimicking a browser's TLS fingerprint (e.g., via JA3), the traffic appears legitimate and may bypass inspection. This approach blends with normal HTTPS traffic, making it harder for the NGFW to distinguish malicious C2 from benign web browsing.

  • ✗

    Configure the C2 client to use a random port above 1024 and implement jitter in the beacon interval to avoid pattern detection.

    Why it's wrong here

    Changing the port and adding jitter might help evade simple port-based or timing-based detection, but it does not address SSL inspection. The NGFW will still decrypt the traffic and identify the self-signed certificate or malicious payload. Jitter and port randomization are useful for evading statistical analysis, but they are insufficient against deep packet inspection that validates certificates.

  • ✗

    Use a domain fronting technique with a popular CDN to hide the true destination, and keep the self-signed certificate.

    Why it's wrong here

    Domain fronting can bypass some network filters by making the SNI and Host header differ, but if the NGFW performs SSL inspection, it will decrypt the traffic and see the self-signed certificate. The certificate would still be untrusted and likely blocked. Additionally, domain fronting requires the CDN to support it, and many have discontinued the practice. Keeping the self-signed certificate is a critical flaw.

  • ✗

    Encapsulate the C2 traffic within DNS queries to a domain you control, using a high volume of queries to avoid detection.

    Why it's wrong here

    While DNS tunneling can evade some firewalls, the scenario states that the NGFW is performing SSL inspection and blocking the current TCP channel. Switching to DNS tunneling is a different protocol, but it may not be allowed if the firewall restricts outbound DNS or if the NGFW also monitors DNS. Moreover, high volumes of DNS queries can trigger anomaly detection. This option does not address the SSL inspection issue directly and may introduce new detection vectors.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.