CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

During an incident review, an analyst finds the following firewall log entries: `10:15:02 OUT 192.168.10.15:49321 -> 45.33.10.7:443 ALLOW` `10:20:04 OUT 192.168.10.15:49325 -> 45.33.10.7:443 ALLOW` `10:25:03 OUT 192.168.10.15:49330 -> 45.33.10.7:443 ALLOW` The internal host contacts the same external IP every 5 minutes with near-identical timing. Which Cyber Kill Chain phase does this activity represent?

  1. ADelivery
  2. BCommand and Control
  3. CExploitation
  4. DWeaponization
Show answer & explanation

Correct answer: B. Command and Control

Regular, periodic outbound connections (beaconing) from a compromised host to an external IP indicate the Command and Control (C2) phase, where malware checks in with an attacker-controlled server for instructions.

Why the other options are wrong

  • A. Delivery is the transmission of the weaponized payload to the victim, not ongoing beaconing.
  • C. Exploitation is the moment the vulnerability is triggered, not repeated post-compromise check-ins.
  • D. Weaponization occurs offline when the attacker builds the malicious payload, before any network traffic.

Command and Control (C2) Phase

The Cyber Kill Chain phase where compromised systems establish a channel back to attacker infrastructure for ongoing control.

  • Often identified by periodic 'beaconing' traffic
  • Same destination IP/domain at regular intervals is a red flag
  • Occurs after successful exploitation and installation

Memory trick: Reconnaissance, Weaponize, Deliver, Exploit, Install, Control, Act.

More Vulnerability Management questions