GPEN Command and Control Practice Question
You are performing an authorized penetration test and have established a C2 channel using HTTPS. To evade network detection, you configure your C2 beacon to use domain fronting. Which of the following best describes how domain fronting masks the true destination of your C2 traffic?
⚠ Common exam trap
The trap here is reversing the SNI and Host header roles, or confusing domain fronting with other evasion techniques like DNS tunneling or P2P.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The TLS SNI field contains the domain of a legitimate high-reputation service, while the HTTP Host header contains the actual C2 domain.
Domain fronting works by manipulating the TLS SNI and HTTP Host header. The SNI, visible during the TLS handshake, points to a legitimate domain hosted on a CDN, while the encrypted Host header points to the actual C2 domain also hosted on the same CDN. This makes the traffic appear to be destined for the legitimate domain to network observers, effectively hiding the C2 communication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The TLS SNI field contains the domain of a legitimate high-reputation service, while the HTTP Host header contains the actual C2 domain.
Why this is correct
Domain fronting exploits the difference between the TLS SNI (which is visible in the clear during the TLS handshake) and the HTTP Host header (which is encrypted). By setting the SNI to a legitimate domain hosted on a CDN and the Host header to the C2 domain also hosted on the same CDN, network observers see only the SNI and assume the traffic is to the legitimate domain. The CDN routes the request based on the Host header to the actual C2 server.
- ✗
The C2 traffic is routed through multiple compromised hosts in a peer-to-peer network, making it difficult to trace back to the origin.
Why it's wrong here
This describes a peer-to-peer (P2P) C2 architecture, where compromised hosts relay traffic. Domain fronting does not involve P2P; it relies on a single CDN to mask the destination. While P2P can also obscure the origin, it is a different concept. The scenario asks specifically about domain fronting, so this option is incorrect.
- ✗
The TLS SNI field contains the actual C2 domain, while the HTTP Host header contains the domain of a legitimate service.
Why it's wrong here
This is the reverse of domain fronting. If the SNI contains the actual C2 domain, network monitoring tools can easily detect the malicious domain during the TLS handshake. The purpose of domain fronting is to hide the true destination, so the SNI must be the legitimate domain, not the C2 domain. Therefore, this configuration would not mask the C2 traffic and is incorrect.
- ✗
The C2 traffic is encapsulated within DNS queries to a legitimate domain, and the responses contain the C2 instructions.
Why it's wrong here
This describes DNS tunneling, not domain fronting. DNS tunneling encodes data in DNS queries and responses, often to a domain controlled by the attacker. Domain fronting, in contrast, uses HTTPS to a legitimate CDN with mismatched SNI and Host headers. The scenario specifically asks about domain fronting, so this option is a distractor based on a different technique.
Visual reference
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.