GPEN Command and Control Practice Question
You are conducting a penetration test against a target that employs a next-generation firewall (NGFW) with SSL inspection. Your C2 channel uses a custom protocol over TCP port 8443 with a self-signed certificate. The NGFW is blocking your traffic. You need to modify your C2 configuration to evade detection while maintaining command and control. Which of the following changes is MOST likely to succeed?
⚠ Common exam trap
The trap here is focusing on network-level obfuscation like jitter or port changes while ignoring that SSL inspection operates at the application layer and will still detect a self-signed certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Switch to using a legitimate code-signing certificate issued by a trusted CA and mimic the TLS fingerprint of a common web browser.
The NGFW's SSL inspection is blocking the C2 because it can decrypt the traffic and detect the self-signed certificate or suspicious TLS characteristics. To evade this, the C2 must present a trusted certificate and mimic a legitimate browser's TLS handshake. This makes the traffic indistinguishable from normal HTTPS. The other options either do not address SSL inspection (jitter, port change) or retain the self-signed certificate (domain fronting), which would still be flagged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Switch to using a legitimate code-signing certificate issued by a trusted CA and mimic the TLS fingerprint of a common web browser.
Why this is correct
SSL inspection decrypts traffic and can block self-signed certificates or anomalous TLS fingerprints. By using a trusted CA certificate and mimicking a browser's TLS fingerprint (e.g., via JA3), the traffic appears legitimate and may bypass inspection. This approach blends with normal HTTPS traffic, making it harder for the NGFW to distinguish malicious C2 from benign web browsing.
- ✗
Configure the C2 client to use a random port above 1024 and implement jitter in the beacon interval to avoid pattern detection.
Why it's wrong here
Changing the port and adding jitter might help evade simple port-based or timing-based detection, but it does not address SSL inspection. The NGFW will still decrypt the traffic and identify the self-signed certificate or malicious payload. Jitter and port randomization are useful for evading statistical analysis, but they are insufficient against deep packet inspection that validates certificates.
- ✗
Use a domain fronting technique with a popular CDN to hide the true destination, and keep the self-signed certificate.
Why it's wrong here
Domain fronting can bypass some network filters by making the SNI and Host header differ, but if the NGFW performs SSL inspection, it will decrypt the traffic and see the self-signed certificate. The certificate would still be untrusted and likely blocked. Additionally, domain fronting requires the CDN to support it, and many have discontinued the practice. Keeping the self-signed certificate is a critical flaw.
- ✗
Encapsulate the C2 traffic within DNS queries to a domain you control, using a high volume of queries to avoid detection.
Why it's wrong here
While DNS tunneling can evade some firewalls, the scenario states that the NGFW is performing SSL inspection and blocking the current TCP channel. Switching to DNS tunneling is a different protocol, but it may not be allowed if the firewall restricts outbound DNS or if the NGFW also monitors DNS. Moreover, high volumes of DNS queries can trigger anomaly detection. This option does not address the SSL inspection issue directly and may introduce new detection vectors.
Visual reference
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.