300-220 · Question #70
To determine the stage of infection within C2 communications, one must analyze:
The correct answer is B. Traffic data patterns. Traffic data patterns (B) reveal C2 infection stages because malware communicates with its command-and-control server in characteristic ways - beaconing intervals, data exfiltration bursts, staging payloads, and lateral movement all leave distinct network signatures that…
Question
To determine the stage of infection within C2 communications, one must analyze:
Options
- AThe size of email attachments
- BTraffic data patterns
- CAntivirus update logs
- DWi-Fi connection strength
How the community answered
(31 responses)- A3% (1)
- B81% (25)
- C10% (3)
- D6% (2)
Explanation
Traffic data patterns (B) reveal C2 infection stages because malware communicates with its command-and-control server in characteristic ways - beaconing intervals, data exfiltration bursts, staging payloads, and lateral movement all leave distinct network signatures that analysts can correlate to specific kill-chain phases.
Why the distractors are wrong:
- A (email attachment size): Delivery method metadata doesn't indicate how far an infection has progressed post-compromise.
- C (antivirus update logs): AV logs reflect detection activity, not active C2 communication stages - and sophisticated malware often evades AV entirely.
- D (Wi-Fi signal strength): A physical layer metric with no bearing on application-layer C2 behavior.
Memory tip: Think "C2 = Conversation" - just like analyzing a conversation reveals its stage (greeting → negotiation → closing), traffic patterns reveal the C2 lifecycle stage. Network behavior is the language malware uses to communicate.
Topics
Community Discussion
No community discussion yet for this question.