nerdexam
GIAC

GCIH · Question #509

Which of the following would be a recommended containment measure taken to prevent a bot infected system from communicating over command and control channels?

The correct answer is C. Setting an egress firewall rule at the host's subnet perimeter. Bot infected systems communicate with C&C servers via outbound connections over many types of protocols and applications. The best way to prevent these communications during containment would be an egress firewall rule. Changing the host's DNS pointer, patching the already…

Malware Analysis & Advanced Persistent Threats

Question

Which of the following would be a recommended containment measure taken to prevent a bot infected system from communicating over command and control channels?

Options

  • AConfiguring a host IPS to block incoming web traffic
  • BUpdating the system to the current patch level
  • CSetting an egress firewall rule at the host's subnet perimeter
  • DChanging the system's DNS pointer to a different IP address

How the community answered

(18 responses)
  • A
    17% (3)
  • B
    6% (1)
  • C
    72% (13)
  • D
    6% (1)

Explanation

Bot infected systems communicate with C&C servers via outbound connections over many types of protocols and applications. The best way to prevent these communications during containment would be an egress firewall rule. Changing the host's DNS pointer, patching the already infected host, and using host IPS to block incoming web traffic wouldn't prevent C&C outbound connections.

Topics

#botnet C2#egress firewall#containment measures#network-level blocking

Community Discussion

No community discussion yet for this question.

Full GCIH Practice