CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A SOC analyst notices that a workstation is sending small, encrypted outbound connections to the same external IP address every 60 seconds, regardless of user activity, even overnight when the machine is idle. Which of the following BEST describes this activity?
- AA legitimate VPN keepalive session
- BBeaconing to a command-and-control server
- CNormal DNS resolution traffic
- DA false positive from a scheduled antivirus update
Show answer & explanationAnswer & explanation
Correct answer: B. Beaconing to a command-and-control server
Regular, periodic outbound connections at a fixed interval regardless of user activity are a classic indicator of malware beaconing to a command-and-control (C2) server to check in or receive instructions. The consistency and timing (even during idle periods) rule out normal user-driven or scheduled maintenance traffic.
Why the other options are wrong
- A. VPN keepalives are usually part of an established, known VPN session, not unexplained traffic to an unknown external IP.
- C. DNS resolution traffic is triggered by lookups, not by a constant timer regardless of activity.
- D. Antivirus updates are typically infrequent and not tied to a fixed 60-second interval around the clock.
Beaconing
Periodic, low-volume network communication from a compromised host to an external command-and-control (C2) server, used to check in for instructions or exfiltrate data.
- Occurs at regular time intervals ('heartbeat')
- Often uses encrypted or obfuscated traffic
- Continues even when the host is idle, distinguishing it from user-driven traffic
Memory trick: Beaconing = a lighthouse blinking every 60 seconds, calling home to its master.