Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security operations center (SOC) analyst is investigating a series of alerts from the intrusion detection system (IDS) indicating possible command-and-control (C2) traffic. The analyst examines network flow logs and notices periodic outbound connections from an internal server to an external IP address every 30 minutes, with each connection transferring exactly 512 bytes. The external IP address has a low reputation score. Which of the following is the MOST likely explanation for this traffic pattern?

⚠ Common exam trap

The trap here is assuming that any periodic outbound traffic is benign, such as software updates, without considering the fixed small payload and low-reputation destination that indicate malicious beaconing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server is infected with malware that is beaconing to a C2 server.

The correct answer is the one identifying malware beaconing. The combination of periodic connections, fixed small payload size, and low-reputation external IP is a classic indicator of command-and-control beaconing. Malware often uses regular intervals to check in with its C2 server, and the small, consistent payload size helps evade detection by not transferring large amounts of data. This pattern is distinct from legitimate traffic like updates or heartbeats, which typically have different characteristics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The server is infected with malware that is beaconing to a C2 server.

    Why this is correct

    Periodic outbound connections at regular intervals with fixed small payloads are characteristic of malware beaconing. The low reputation of the external IP further supports this. Beaconing allows attackers to maintain command and control while blending into normal traffic. The consistent 30-minute interval and 512-byte size suggest automated communication, which is typical for malware checking in with its C2 infrastructure.

  • ✗

    The server is exfiltrating data in small chunks to avoid detection.

    Why it's wrong here

    Data exfiltration often involves larger or variable amounts of data, even if split into chunks. While exfiltration can be slow and low-profile, the periodic, fixed-size 512-byte transfers are more consistent with beaconing than with exfiltration. Exfiltration would likely show a higher volume over time or irregular patterns. The low reputation IP and regular interval strongly point to C2 beaconing rather than exfiltration.

  • ✗

    The server is performing legitimate software updates from a vendor's server.

    Why it's wrong here

    Legitimate software updates typically involve larger, variable-sized downloads and occur at irregular intervals or on a schedule that is not precisely every 30 minutes. While updates can be periodic, the fixed 512-byte payload is too small for meaningful updates and is more indicative of a heartbeat or check-in. Additionally, a low-reputation IP is unusual for a legitimate vendor, though reputation scores can sometimes be inaccurate.

  • ✗

    The server is sending heartbeat signals to a load balancer for high availability.

    Why it's wrong here

    Heartbeat signals to a load balancer are typically internal to the network or to a known, trusted IP address. They are also usually smaller and more frequent, such as every few seconds. The external destination with a low reputation score does not align with a legitimate load balancer. Furthermore, load balancer heartbeats are not typically flagged by IDS as potential C2 traffic.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.