nerdexam
Cisco

300-220 · Question #70

To determine the stage of infection within C2 communications, one must analyze:

The correct answer is B. Traffic data patterns. Traffic data patterns (B) reveal C2 infection stages because malware communicates with its command-and-control server in characteristic ways - beaconing intervals, data exfiltration bursts, staging payloads, and lateral movement all leave distinct network signatures that…

Threat Hunting Techniques

Question

To determine the stage of infection within C2 communications, one must analyze:

Options

  • AThe size of email attachments
  • BTraffic data patterns
  • CAntivirus update logs
  • DWi-Fi connection strength

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    81% (25)
  • C
    10% (3)
  • D
    6% (2)

Explanation

Traffic data patterns (B) reveal C2 infection stages because malware communicates with its command-and-control server in characteristic ways - beaconing intervals, data exfiltration bursts, staging payloads, and lateral movement all leave distinct network signatures that analysts can correlate to specific kill-chain phases.

Why the distractors are wrong:

  • A (email attachment size): Delivery method metadata doesn't indicate how far an infection has progressed post-compromise.
  • C (antivirus update logs): AV logs reflect detection activity, not active C2 communication stages - and sophisticated malware often evades AV entirely.
  • D (Wi-Fi signal strength): A physical layer metric with no bearing on application-layer C2 behavior.

Memory tip: Think "C2 = Conversation" - just like analyzing a conversation reveals its stage (greeting → negotiation → closing), traffic patterns reveal the C2 lifecycle stage. Network behavior is the language malware uses to communicate.

Topics

#C2 Communications#Traffic Analysis#Infection Stages#Network Detection

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice