300-220 · Question #82
Identifying C2 communications requires analysis of:
The correct answer is B. Application, processes, and logs. Command and Control (C2) communications - the channels attackers use to remotely control compromised systems - leave traces across applications, processes, and logs (B), making these the primary artifacts analysts examine: suspicious network connections in process listings…
Question
Identifying C2 communications requires analysis of:
Options
- AEmployee satisfaction surveys
- BApplication, processes, and logs
- CMarketing campaign effectiveness
- DFinancial transaction logs
How the community answered
(17 responses)- B88% (15)
- C6% (1)
- D6% (1)
Explanation
Command and Control (C2) communications - the channels attackers use to remotely control compromised systems - leave traces across applications, processes, and logs (B), making these the primary artifacts analysts examine: suspicious network connections in process listings, unusual outbound traffic patterns in application logs, and anomalous scheduled tasks or spawned processes all reveal C2 activity. Options A (employee satisfaction surveys) and C (marketing campaign effectiveness) are business/HR metrics with no relevance to network threat detection. Option D (financial transaction logs) tracks monetary activity and belongs to fraud investigation, not intrusion analysis. Memory tip: Think "APL = Active Persistent Listener" - Applications, Processes, and Logs are exactly where a persistent C2 listener hides its footprints.
Topics
Community Discussion
No community discussion yet for this question.