nerdexam
Cisco

700-270 · Question #69

Connections to known CnC sites are an example of which loC event category?

The correct answer is B. IPS. IPS (Intrusion Prevention System) is the correct IoC event category for connections to known Command and Control (CnC) sites because IPS engines use signature-based detection to identify and flag network traffic patterns that match known malicious C&C infrastructure. When a host

Understanding Next-Generation Firewall Technology and Concepts

Question

Connections to known CnC sites are an example of which loC event category?

Options

  • Afirewall
  • BIPS
  • Csecurity intelligence
  • Dmalware

How the community answered

(58 responses)
  • A
    7% (4)
  • B
    88% (51)
  • C
    2% (1)
  • D
    3% (2)

Explanation

IPS (Intrusion Prevention System) is the correct IoC event category for connections to known Command and Control (CnC) sites because IPS engines use signature-based detection to identify and flag network traffic patterns that match known malicious C&C infrastructure. When a host initiates a connection matching a CnC signature, the IPS generates an alert that gets correlated as an IoC event, indicating the host may be compromised.

Why the distractors are wrong:

  • A. Firewall - Firewall IoC events relate to policy violations and traffic blocking based on rules, not behavioral indicators of compromise tied to known threat infrastructure.
  • C. Security Intelligence - While Security Intelligence feeds inform threat detection by maintaining lists of known bad IPs/domains, the IoC event category for the actual CnC connection is attributed to IPS, not SI itself.
  • D. Malware - Malware IoC events are triggered by file-based detections (malicious files downloaded or executed), not network connection activity.

Memory tip: Think "IPS = network behavior caught in the act." CnC connections are live network events - IPS watches traffic in real time and catches the host "phoning home," making it the right category. Malware = files, Firewall = policy, Security Intelligence = the threat list behind the scenes.

Topics

#Command and Control (CnC)#IPS Detection#Threat Intelligence#NGFW Security

Community Discussion

No community discussion yet for this question.

Full 700-270 Practice