GPEN Command and Control Practice Question
You are using Cobalt Strike in an authorized penetration test. The target network uses a next-generation firewall that performs SSL inspection and blocks self-signed certificates. You need to configure your HTTPS beacon to blend in with legitimate traffic and avoid detection. (Choose two.)
⚠ Common exam trap
The trap here is focusing solely on traffic shaping (sleep/jitter) or user agent strings while overlooking the need for a trusted certificate to pass SSL inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the beacon to use a malleable C2 profile that mimics a known application like Microsoft Outlook Web Access.
To evade SSL inspection and blend in, using a valid certificate from a trusted CA ensures the TLS handshake is accepted, and a malleable C2 profile mimicking a known application like OWA makes the traffic appear legitimate at the application layer. Together, they address both certificate trust and traffic pattern detection. Other options do not resolve the certificate blocking or are less effective for blending.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the TCP beacon instead of the HTTPS beacon.
Why it's wrong here
Switching to a TCP beacon abandons TLS entirely, which may be blocked by the firewall if it enforces HTTPS on port 443 or inspects protocols. The scenario involves SSL inspection, so using a non-TLS protocol may trigger other alerts or be blocked outright. TCP beacons are also less likely to blend in with web traffic. This does not solve the certificate issue and may introduce new problems.
- ✗
Use a self-signed certificate but set the beacon's user agent to match a common browser.
Why it's wrong here
The firewall blocks self-signed certificates regardless of the user agent. Changing the user agent does not affect the certificate's trust status. While a legitimate user agent can help with application-layer blending, it does not bypass SSL inspection that checks certificate validity. Therefore, this option fails to address the core issue of self-signed certificate blocking.
- ✗
Set the beacon's sleep time to 60 seconds with 30% jitter.
Why it's wrong here
While sleep and jitter affect beacon timing and can help evade behavioral detection, they do not address SSL inspection or certificate blocking. The scenario specifically mentions SSL inspection and self-signed certificate blocking. Adjusting sleep and jitter may reduce the chance of anomaly detection but will not prevent the firewall from blocking the self-signed certificate. Thus, it is not directly relevant to the stated problem.
- ✓
Configure the beacon to use a malleable C2 profile that mimics a known application like Microsoft Outlook Web Access.
Why this is correct
A malleable C2 profile customizes the beacon's network traffic to resemble a legitimate application. By mimicking Outlook Web Access, the traffic's HTTP headers, URIs, and other characteristics match normal OWA usage. This helps evade deep packet inspection and application-based blocking, complementing the valid certificate. It makes the beacon traffic blend in with expected enterprise traffic, reducing the chance of detection.
- ✓
Use a valid SSL certificate from a trusted certificate authority for the C2 listener.
Why this is correct
A valid certificate from a trusted CA ensures that the TLS handshake is not flagged as self-signed. The firewall's SSL inspection will see a legitimate certificate and allow the traffic. This directly addresses the blocking of self-signed certificates and helps the beacon blend in with normal HTTPS traffic. It is a fundamental step for evading SSL inspection.
Visual reference
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.