CompTIA CySA+ (CS0-003)Security OperationsMedium

During threat hunting, an analyst reviews proxy logs and finds a workstation sending an outbound HTTPS request to the same external IP address every 60 seconds, each request transferring nearly identical byte counts, 24 hours a day, even outside business hours. Which indicator of malicious activity does this pattern most strongly suggest?

  1. ACommand-and-control beaconing
  2. BData exfiltration via DNS tunneling
  3. CNormal cloud backup synchronization
  4. DA misconfigured software update client
Show answer & explanation

Correct answer: A. Command-and-control beaconing

Highly regular, fixed-interval connections to a single external host with consistent payload sizes—regardless of user activity or business hours—is the classic signature of malware beaconing to a C2 server.

Why the other options are wrong

  • B. DNS tunneling would appear in DNS query logs with encoded subdomains, not regular HTTPS sessions.
  • C. Backup sync traffic usually varies in size and timing based on data changes, not fixed identical intervals.
  • D. Legitimate update clients typically check periodically but not at such a rigid fixed 60-second cadence continuously.

C2 Beaconing

Regular, periodic outbound communication from a compromised host to an external command-and-control server, often with consistent timing and payload size.

  • Fixed time intervals regardless of user activity
  • Often uses HTTPS/DNS to blend with normal traffic
  • Detected via traffic analysis for periodicity/jitter patterns

Memory trick: Like a heartbeat, malware beacons keep steady rhythm.

More Security Operations questions