CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
During an incident review, an analyst finds the following firewall log entries: `10:15:02 OUT 192.168.10.15:49321 -> 45.33.10.7:443 ALLOW` `10:20:04 OUT 192.168.10.15:49325 -> 45.33.10.7:443 ALLOW` `10:25:03 OUT 192.168.10.15:49330 -> 45.33.10.7:443 ALLOW` The internal host contacts the same external IP every 5 minutes with near-identical timing. Which Cyber Kill Chain phase does this activity represent?
- ADelivery
- BCommand and Control
- CExploitation
- DWeaponization
Show answer & explanationAnswer & explanation
Correct answer: B. Command and Control
Regular, periodic outbound connections (beaconing) from a compromised host to an external IP indicate the Command and Control (C2) phase, where malware checks in with an attacker-controlled server for instructions.
Why the other options are wrong
- A. Delivery is the transmission of the weaponized payload to the victim, not ongoing beaconing.
- C. Exploitation is the moment the vulnerability is triggered, not repeated post-compromise check-ins.
- D. Weaponization occurs offline when the attacker builds the malicious payload, before any network traffic.
Command and Control (C2) Phase
The Cyber Kill Chain phase where compromised systems establish a channel back to attacker infrastructure for ongoing control.
- Often identified by periodic 'beaconing' traffic
- Same destination IP/domain at regular intervals is a red flag
- Occurs after successful exploitation and installation
Memory trick: Reconnaissance, Weaponize, Deliver, Exploit, Install, Control, Act.