HPE6-A84 · Question #11
What is a common characteristic of a beacon between a compromised device and a command and control server?
The correct answer is D. Periodic transmission of small, identically sized packets. A beacon is a type of network traffic that is sent from a compromised device to a command and control (C2) server, which is a remote system that controls the malicious activities of the device . A beacon is used to establish and maintain communication between the device and the…
Question
What is a common characteristic of a beacon between a compromised device and a command and control server?
Options
- AUse of IPv6 addressing instead of IPv4 addressing
- BLack of encryption
- CUse of less common protocols such as SNAP
- DPeriodic transmission of small, identically sized packets
How the community answered
(31 responses)- B6% (2)
- C3% (1)
- D90% (28)
Explanation
A beacon is a type of network traffic that is sent from a compromised device to a command and control (C2) server, which is a remote system that controls the malicious activities of the device . A beacon is used to establish and maintain communication between the device and the C2 server, as well as to receive instructions or exfiltrate data . A common characteristic of a beacon is that it is periodic, meaning that it is sent at regular intervals, such as every few minutes or hours . This helps the C2 server to monitor the status and availability of the device, as well as to avoid detection by network security tools . Another common characteristic of a beacon is that it is small and identically sized, meaning that it contains minimal or fixed amount of data, such as a simple acknowledgment or a random string. This helps the device to conserve bandwidth and resources, as well as to avoid detection by network
Topics
Community Discussion
No community discussion yet for this question.