CompTIA CySA+ (CS0-003)Security OperationsMedium
During threat hunting, an analyst reviews proxy logs and finds a workstation sending an outbound HTTPS request to the same external IP address every 60 seconds, each request transferring nearly identical byte counts, 24 hours a day, even outside business hours. Which indicator of malicious activity does this pattern most strongly suggest?
- ACommand-and-control beaconing
- BData exfiltration via DNS tunneling
- CNormal cloud backup synchronization
- DA misconfigured software update client
Show answer & explanationAnswer & explanation
Correct answer: A. Command-and-control beaconing
Highly regular, fixed-interval connections to a single external host with consistent payload sizes—regardless of user activity or business hours—is the classic signature of malware beaconing to a C2 server.
Why the other options are wrong
- B. DNS tunneling would appear in DNS query logs with encoded subdomains, not regular HTTPS sessions.
- C. Backup sync traffic usually varies in size and timing based on data changes, not fixed identical intervals.
- D. Legitimate update clients typically check periodically but not at such a rigid fixed 60-second cadence continuously.
C2 Beaconing
Regular, periodic outbound communication from a compromised host to an external command-and-control server, often with consistent timing and payload size.
- Fixed time intervals regardless of user activity
- Often uses HTTPS/DNS to blend with normal traffic
- Detected via traffic analysis for periodicity/jitter patterns
Memory trick: Like a heartbeat, malware beacons keep steady rhythm.