Courseiva
Command and Control →hardMultiple Choice

GPEN Command and Control Practice Question

You are performing an authorized penetration test and have established a C2 channel using HTTPS. To evade network detection, you configure your C2 beacon to use domain fronting. Which of the following best describes how domain fronting masks the true destination of your C2 traffic?

⚠ Common exam trap

The trap here is reversing the SNI and Host header roles, or confusing domain fronting with other evasion techniques like DNS tunneling or P2P.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The TLS SNI field contains the domain of a legitimate high-reputation service, while the HTTP Host header contains the actual C2 domain.

Domain fronting works by manipulating the TLS SNI and HTTP Host header. The SNI, visible during the TLS handshake, points to a legitimate domain hosted on a CDN, while the encrypted Host header points to the actual C2 domain also hosted on the same CDN. This makes the traffic appear to be destined for the legitimate domain to network observers, effectively hiding the C2 communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The TLS SNI field contains the domain of a legitimate high-reputation service, while the HTTP Host header contains the actual C2 domain.

    Why this is correct

    Domain fronting exploits the difference between the TLS SNI (which is visible in the clear during the TLS handshake) and the HTTP Host header (which is encrypted). By setting the SNI to a legitimate domain hosted on a CDN and the Host header to the C2 domain also hosted on the same CDN, network observers see only the SNI and assume the traffic is to the legitimate domain. The CDN routes the request based on the Host header to the actual C2 server.

  • ✗

    The C2 traffic is routed through multiple compromised hosts in a peer-to-peer network, making it difficult to trace back to the origin.

    Why it's wrong here

    This describes a peer-to-peer (P2P) C2 architecture, where compromised hosts relay traffic. Domain fronting does not involve P2P; it relies on a single CDN to mask the destination. While P2P can also obscure the origin, it is a different concept. The scenario asks specifically about domain fronting, so this option is incorrect.

  • ✗

    The TLS SNI field contains the actual C2 domain, while the HTTP Host header contains the domain of a legitimate service.

    Why it's wrong here

    This is the reverse of domain fronting. If the SNI contains the actual C2 domain, network monitoring tools can easily detect the malicious domain during the TLS handshake. The purpose of domain fronting is to hide the true destination, so the SNI must be the legitimate domain, not the C2 domain. Therefore, this configuration would not mask the C2 traffic and is incorrect.

  • ✗

    The C2 traffic is encapsulated within DNS queries to a legitimate domain, and the responses contain the C2 instructions.

    Why it's wrong here

    This describes DNS tunneling, not domain fronting. DNS tunneling encodes data in DNS queries and responses, often to a domain controlled by the attacker. Domain fronting, in contrast, uses HTTPS to a legitimate CDN with mismatched SNI and Host headers. The scenario specifically asks about domain fronting, so this option is a distractor based on a different technique.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.