Courseiva
Command and Control →mediumMultiple Select

GPEN Command and Control Practice Question

You are designing a resilient command-and-control (C2) infrastructure for an authorized penetration test. The client's network has strict egress filtering and monitors for anomalous traffic. You need to ensure that your C2 channel can survive the takedown of a single server and adapt to changing network conditions. Which two of the following techniques should you implement? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse stealth techniques like jitter with resilience techniques; jitter helps avoid detection but does not help if the C2 server is taken offline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a fallback channel that uses a different protocol (e.g., DNS) if the primary channel is blocked.

Resilient C2 infrastructure requires redundancy and adaptability. Multiple redirectors with domain fronting provide redundancy and hide the true server, making takedown more difficult. A fallback channel using a different protocol ensures communication continues if the primary channel is blocked. These two techniques directly address survivability and adaptability. The other options either introduce single points of failure or focus on stealth rather than resilience.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a fallback channel that uses a different protocol (e.g., DNS) if the primary channel is blocked.

    Why this is correct

    A fallback channel provides an alternative communication path if the primary protocol is blocked or degraded. For example, if HTTPS is blocked, the client can switch to DNS tunneling. This adaptability ensures continued command and control even when network conditions change or defenses are updated. It is a key component of resilient C2 design.

  • ✗

    Enable jitter and sleep intervals to randomize beacon timing and avoid pattern-based detection.

    Why it's wrong here

    Jitter and sleep intervals help evade timing-based detection, but they do not directly contribute to survivability against server takedown or network changes. They are useful for stealth, but the question asks for techniques to survive takedown and adapt to changing conditions. While important, this option does not address redundancy or fallback capabilities.

  • ✓

    Use multiple redirectors with domain fronting to distribute traffic and hide the true C2 server.

    Why this is correct

    Multiple redirectors distribute the load and provide redundancy; if one redirector is taken down, others can still forward traffic. Domain fronting hides the true destination behind a CDN, making it harder for defenders to block the C2 server directly. This combination increases resilience and survivability against takedown attempts.

  • ✗

    Configure the C2 client to use a single hardcoded IP address for the C2 server to simplify reconnection.

    Why it's wrong here

    A single hardcoded IP address is a single point of failure. If that server is taken down or blocked, the C2 channel is lost. Resilience requires redundancy, such as multiple IPs or domain names. Hardcoding also makes it easier for defenders to block the known IP. This approach reduces survivability and is not recommended for resilient C2.

  • ✗

    Use a single domain name with a long TTL to minimize DNS lookups and reduce the chance of detection.

    Why it's wrong here

    A single domain name is a single point of failure; if it is sinkholed or blocked, the C2 channel fails. A long TTL might reduce DNS lookups, but it also means that if the domain is compromised, the client will continue to use it for a long time, hindering recovery. Resilience requires multiple domains or fast flux, not a single domain with long TTL.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.