ISC2 CC Security Operations Practice Question
A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any encrypted traffic to an unfamiliar IP is malicious, when encryption and self-signed certificates are also common in legitimate internal and cloud services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic uses domain fronting to hide the true destination.
Beaconing behavior, such as regular intervals with consistent packet sizes, is a hallmark of automated C2 communication. Domain fronting, which disguises the true destination by manipulating SNI and Host headers, is another technique frequently used by malware to evade network defenses. Both are strong indicators of malicious C2 activity, whereas cloud-hosted IPs, service-initiated connections, and self-signed certificates can also be legitimate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The traffic uses domain fronting to hide the true destination.
Why this is correct
Domain fronting is a technique where the SNI and HTTP Host header differ, allowing traffic to appear as if it is destined for a legitimate domain while actually communicating with a different server. This is commonly used by malware to evade detection. Its presence is a strong indicator of malicious C2 activity, making this a correct characteristic.
- ✗
The connections are initiated by a server process running as a system service.
Why it's wrong here
Legitimate server processes often initiate outbound connections for updates, licensing, or telemetry. While malware can also run as a service, this alone is not a reliable indicator of C2. Many benign services behave similarly, so this characteristic is not specific enough to flag as malicious.
- ✗
The traffic is encrypted and uses a self-signed certificate.
Why it's wrong here
Encrypted traffic with a self-signed certificate is common in internal applications and development environments. While attackers may use self-signed certificates, it is not a definitive indicator of C2. Legitimate services sometimes use them, so this characteristic alone does not strongly suggest malicious activity.
- ✓
The traffic occurs at regular intervals with consistent packet sizes.
Why this is correct
C2 channels often use beaconing, where the compromised host periodically checks in with the C2 server. This results in traffic at regular intervals with consistent packet sizes, which is a strong indicator of automated malicious communication. Such patterns are unusual for legitimate user-driven traffic, making this a correct characteristic.
- ✗
The external IP address is associated with a known cloud service provider.
Why it's wrong here
Many legitimate services are hosted on cloud providers, so an IP belonging to a cloud service is not inherently malicious. Attackers may use cloud services, but this alone is not a reliable indicator. Therefore, this characteristic does not strongly suggest C2 activity and is not a correct choice.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Security operations center
A Security Operations Center (SOC) is a centralized team and facility that monitors, detects, analyzes, and responds to cybersecurity incidents across an organization's IT environment 24/7.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.