Courseiva
Security Operations →hardMultiple Select

ISC2 CC Security Operations Practice Question

A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any encrypted traffic to an unfamiliar IP is malicious, when encryption and self-signed certificates are also common in legitimate internal and cloud services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The traffic uses domain fronting to hide the true destination.

Beaconing behavior, such as regular intervals with consistent packet sizes, is a hallmark of automated C2 communication. Domain fronting, which disguises the true destination by manipulating SNI and Host headers, is another technique frequently used by malware to evade network defenses. Both are strong indicators of malicious C2 activity, whereas cloud-hosted IPs, service-initiated connections, and self-signed certificates can also be legitimate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The traffic uses domain fronting to hide the true destination.

    Why this is correct

    Domain fronting is a technique where the SNI and HTTP Host header differ, allowing traffic to appear as if it is destined for a legitimate domain while actually communicating with a different server. This is commonly used by malware to evade detection. Its presence is a strong indicator of malicious C2 activity, making this a correct characteristic.

  • ✗

    The connections are initiated by a server process running as a system service.

    Why it's wrong here

    Legitimate server processes often initiate outbound connections for updates, licensing, or telemetry. While malware can also run as a service, this alone is not a reliable indicator of C2. Many benign services behave similarly, so this characteristic is not specific enough to flag as malicious.

  • ✗

    The traffic is encrypted and uses a self-signed certificate.

    Why it's wrong here

    Encrypted traffic with a self-signed certificate is common in internal applications and development environments. While attackers may use self-signed certificates, it is not a definitive indicator of C2. Legitimate services sometimes use them, so this characteristic alone does not strongly suggest malicious activity.

  • ✓

    The traffic occurs at regular intervals with consistent packet sizes.

    Why this is correct

    C2 channels often use beaconing, where the compromised host periodically checks in with the C2 server. This results in traffic at regular intervals with consistent packet sizes, which is a strong indicator of automated malicious communication. Such patterns are unusual for legitimate user-driven traffic, making this a correct characteristic.

  • ✗

    The external IP address is associated with a known cloud service provider.

    Why it's wrong here

    Many legitimate services are hosted on cloud providers, so an IP belonging to a cloud service is not inherently malicious. Attackers may use cloud services, but this alone is not a reliable indicator. Therefore, this characteristic does not strongly suggest C2 activity and is not a correct choice.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.