PSE-STRATA · Question #172
In Panorama, which three reports or logs will help identify the inclusion of a host source in a command-and-control (C2) incident? (Choose three.)
The correct answer is C. WildFire analysis reports D. threat logs E. botnet reports. WildFire Analysis Reports (C), Threat Logs (D), and Botnet Reports (E) are the correct trio because they directly surface C2-related indicators. WildFire analyzes suspicious files and URLs and flags malware that often establishes C2 channels. Threat logs record detected…
Question
In Panorama, which three reports or logs will help identify the inclusion of a host source in a command-and-control (C2) incident? (Choose three.)
Options
- ASaaS reports
- Bdata filtering logs
- CWildFire analysis reports
- Dthreat logs
- Ebotnet reports
How the community answered
(46 responses)- A17% (8)
- B9% (4)
- C74% (34)
Explanation
WildFire Analysis Reports (C), Threat Logs (D), and Botnet Reports (E) are the correct trio because they directly surface C2-related indicators. WildFire analyzes suspicious files and URLs and flags malware that often establishes C2 channels. Threat logs record detected exploits, malware callbacks, and command-and-control traffic in real time. Botnet reports specifically identify hosts exhibiting botnet/C2 behavior - such as repeated DNS lookups, IRC traffic, or unknown application usage patterns consistent with infected endpoints.
Why the distractors are wrong:
- A (SaaS reports): These focus on sanctioned/unsanctioned cloud application usage, not malware or C2 activity.
- B (Data filtering logs): These track data-loss-prevention events (e.g., SSNs or credit cards leaving the network), not command-and-control communication.
Memory tip: Think "WTB" - WildFire, Threat, Botnet. All three names literally contain the concept of malicious activity. SaaS = cloud apps, Data filtering = DLP - neither word sounds like an attack, which is your cue to eliminate them.
Topics
Community Discussion
No community discussion yet for this question.