Courseiva
Command and Control →mediumMultiple Select

GPEN Command and Control Practice Question

You are configuring a C2 listener to use a malleable profile to blend in with legitimate traffic. Which two of the following are key benefits of using a malleable C2 profile in a penetration test? (Choose two.)

⚠ Common exam trap

The trap here is assuming malleable profiles provide encryption or domain generation, which are separate techniques, rather than focusing on traffic shaping and customization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides a mechanism to define how the C2 server responds to specific requests, including error pages and other decoy content.

Malleable C2 profiles are used to customize the network traffic generated by a C2 framework to evade detection. They allow operators to define request and response structures, including headers, URIs, and body content, so that the traffic mimics legitimate services. This customization helps in blending with normal network activity and avoiding signature-based detection, making it a valuable tool during penetration tests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It enables the C2 server to automatically generate new domain names for each beacon, avoiding domain blacklisting.

    Why it's wrong here

    Automatic domain generation is a feature of domain generation algorithms (DGAs), not malleable C2 profiles. Malleable profiles focus on the content and structure of network requests, not on dynamically changing domains. While DGAs can be used in conjunction with C2, they are a separate technique. Thus, this is not a benefit of malleable profiles.

  • ✓

    It provides a mechanism to define how the C2 server responds to specific requests, including error pages and other decoy content.

    Why this is correct

    Malleable C2 profiles allow operators to specify server responses, such as HTTP status codes, headers, and body content. This can include decoy pages or error messages that make the C2 server appear as a legitimate web server. By controlling responses, operators can further blend in and mislead defenders. This is a key benefit for maintaining stealth during a penetration test.

  • ✗

    It encrypts the C2 traffic using a unique, randomly generated key for each session, ensuring perfect forward secrecy.

    Why it's wrong here

    While many C2 frameworks support encryption, malleable profiles do not inherently provide unique session keys or perfect forward secrecy. Encryption is typically handled by the payload or the framework's transport layer, not by the profile itself. The profile defines the traffic's appearance, not its cryptographic properties. Therefore, this is not a key benefit of malleable profiles.

  • ✗

    It allows the C2 traffic to be routed through multiple redirectors without additional configuration.

    Why it's wrong here

    Malleable profiles do not inherently handle redirector routing. Redirectors are separate infrastructure components that forward traffic to the C2 server, and their configuration is independent of the profile. While profiles can be used with redirectors, the profile itself does not enable or simplify routing through multiple redirectors. Therefore, this is not a key benefit.

  • ✓

    It allows you to customize the HTTP headers, URIs, and other request parameters to mimic a specific application or service.

    Why this is correct

    Malleable C2 profiles enable operators to define the exact structure of C2 traffic, including HTTP headers, URIs, and other parameters. This customization allows the traffic to closely resemble legitimate applications, such as Microsoft Update or Google services, making it harder for network defenders to distinguish malicious traffic from benign. This is a primary benefit for evading detection during a penetration test.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.