nerdexam
Cisco

300-220 · Question #82

Identifying C2 communications requires analysis of:

The correct answer is B. Application, processes, and logs. Command and Control (C2) communications - the channels attackers use to remotely control compromised systems - leave traces across applications, processes, and logs (B), making these the primary artifacts analysts examine: suspicious network connections in process listings…

Threat Hunting Techniques

Question

Identifying C2 communications requires analysis of:

Options

  • AEmployee satisfaction surveys
  • BApplication, processes, and logs
  • CMarketing campaign effectiveness
  • DFinancial transaction logs

How the community answered

(17 responses)
  • B
    88% (15)
  • C
    6% (1)
  • D
    6% (1)

Explanation

Command and Control (C2) communications - the channels attackers use to remotely control compromised systems - leave traces across applications, processes, and logs (B), making these the primary artifacts analysts examine: suspicious network connections in process listings, unusual outbound traffic patterns in application logs, and anomalous scheduled tasks or spawned processes all reveal C2 activity. Options A (employee satisfaction surveys) and C (marketing campaign effectiveness) are business/HR metrics with no relevance to network threat detection. Option D (financial transaction logs) tracks monetary activity and belongs to fraud investigation, not intrusion analysis. Memory tip: Think "APL = Active Persistent Listener" - Applications, Processes, and Logs are exactly where a persistent C2 listener hides its footprints.

Topics

#C2 Communications#Log Analysis#Threat Hunting#Malware Detection

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice