Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A network administrator observes unusual outbound connections from several internal workstations to an external IP address known to be associated with command-and-control (C2) servers. These connections are occurring even when users are not actively browsing. Which type of malware is most likely responsible for this behavior?
- AAdware
- BRootkit
- CRansomware
- DBotnet
Show answer & explanationAnswer & explanation
Correct answer: D. Botnet
Outbound connections to C2 servers indicate that the compromised machines are part of a botnet, awaiting instructions from a central command. This behavior is characteristic of bots being controlled remotely.
Why the other options are wrong
- A. Adware displays unwanted advertisements, not typically connecting to C2 servers.
- B. Rootkits hide malicious activity but don't inherently create outbound C2 connections for remote control.
- C. Ransomware encrypts data and demands payment, typically not establishing C2 connections for ongoing control.
Botnet
A botnet is a network of compromised computers (bots) controlled by a single attacking party (the 'bot herder'). These bots are often used to launch Distributed Denial-of-Service (DDoS) attacks, send spam, or spread other malware.
- Comprised of multiple 'zombie' or 'bot' computers.
- Controlled by a C2 (command-and-control) server.
- Often used for large-scale malicious activities without user knowledge.
Memory trick: Malware: Ransomware locks, Adware nags, Bots obey.