Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A network administrator observes unusual outbound connections from several internal workstations to an external IP address known to be associated with command-and-control (C2) servers. These connections are occurring even when users are not actively browsing. Which type of malware is most likely responsible for this behavior?

  1. AAdware
  2. BRootkit
  3. CRansomware
  4. DBotnet
Show answer & explanation

Correct answer: D. Botnet

Outbound connections to C2 servers indicate that the compromised machines are part of a botnet, awaiting instructions from a central command. This behavior is characteristic of bots being controlled remotely.

Why the other options are wrong

  • A. Adware displays unwanted advertisements, not typically connecting to C2 servers.
  • B. Rootkits hide malicious activity but don't inherently create outbound C2 connections for remote control.
  • C. Ransomware encrypts data and demands payment, typically not establishing C2 connections for ongoing control.

Botnet

A botnet is a network of compromised computers (bots) controlled by a single attacking party (the 'bot herder'). These bots are often used to launch Distributed Denial-of-Service (DDoS) attacks, send spam, or spread other malware.

  • Comprised of multiple 'zombie' or 'bot' computers.
  • Controlled by a C2 (command-and-control) server.
  • Often used for large-scale malicious activities without user knowledge.

Memory trick: Malware: Ransomware locks, Adware nags, Bots obey.

More Security Principles questions