Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesHard

A cybersecurity analyst detects unusual outgoing network traffic from several workstations, indicating communication with known command-and-control (C2) servers. Further investigation reveals that these workstations have been infected with malicious software that is collecting data and awaiting further instructions. This scenario most clearly indicates an infection by which type of common security threat?

  1. APhishing
  2. BBotnet
  3. CRansomware
  4. DSpyware
Show answer & explanation

Correct answer: B. Botnet

The key indicators are 'infected with malicious software', 'collecting data', and 'awaiting further instructions' from 'command-and-control (C2) servers'. This describes a botnet, where compromised machines (bots) are controlled remotely by an attacker (bot-herder) to perform coordinated malicious activities.

Why the other options are wrong

  • A. Phishing is a delivery method for malware, not the type of malware itself, and doesn't fully capture the C2 aspect.
  • C. Ransomware encrypts data for ransom, which is not described by 'collecting data and awaiting instructions'.
  • D. Spyware collects information, but the 'awaiting further instructions' from C2 servers points to remote control, a hallmark of botnets.

Botnet

A network of compromised computers (bots) controlled by a threat actor (bot-herder) via a command-and-control (C2) server.

  • Used for coordinated attacks (DoS, spam, data theft).
  • Infected machines 'phone home' to C2 servers.
  • Users are often unaware their machine is part of a botnet.

Memory trick: Malware types: Virus spreads, Worm replicates, Ransomware locks, Spyware watches, Botnet obeys.

More Security Principles questions